Declic Services: 6.2 million rows claimed, roughly 15,000 real accounts
ZeroBytes claims 6.27 million rows at Declic Services via a
WordPress β ERP β production database attack chain. After deduplication, the hacker
itself cites roughly 15,000 unique accounts. Unconfirmed.
β οΈ Claimed, unconfirmed β and a figure not to take at
face value. The hacker ZeroBytes claims the attack, but the most eye-catching
figure (6.2 million) is a raw-row count, not a people count. This case file details the
gap.
The numbers
6.27M
Raw, undeduplicated rows claimed β the figure that circulates, but
not the number of people affected.
ZeroBytes claim, unconfirmed.
14,947
Unique email addresses claimed after deduplication β the real order
of magnitude, according to the hacker itself.
ZeroBytes claim, unconfirmed.
6,451
Unique IBANs claimed, out of roughly 6,300 total client/IBAN
identifiers.
ZeroBytes claim, unconfirmed.
3
Steps in the described attack chain: public WordPress site β
exposed ERP β production database and cloud infrastructure.
ZeroBytes claim.
Timeline
CLAIMED
August 20, 2026 (alleged intrusion)
According to ZeroBytes, the intrusion started with a publicly
accessible WordPress site, leading to an exposed ERP system, then Declic Services'
production database and cloud infrastructure.
CLAIMED
August 22, 2026
ZeroBytes publishes the claim: 6,271,531 raw rows, containing
identities, contact details, postal addresses, emails, IBAN/RIB, BIC codes, URSSAF
payment data, billing information, financial records, password hashes, contracts and
internal configuration details.
UNCONFIRMED
Since
No public confirmation from Declic Services has been identified
to date. The deduplicated count β roughly 14,947 unique emails and 6,451 unique IBANs
β comes from the hacker itself, not an independent verification.
π’Raw rows versus real people: a 400x gap
This case file illustrates a common reading trap in hacker claims: the headline
figure (6.2 million) is a database row count, not a count of distinct people. The same
person can appear across dozens of rows (contracts, invoices, exchanges). The
deduplicated figure β roughly 15,000 β remains the more honest order of magnitude, and
it comes from the hacker itself, proof that even a claim benefits from distinguishing
the two measures.
What it changes for you
If you're a Declic Services customer, your contact details and IBAN could be among the
roughly 15,000 unique accounts claimed β pending confirmation. The main risk is
wire-transfer fraud or phishing citing a real contract or invoice. See
From Leak to Scam.
π Always verify through an independent channel any request to
change bank details, even if the message cites an exact contract or invoice number.
Frequently asked questions
Is the Declic Services leak confirmed?
No, it's a claim by ZeroBytes, with no public confirmation from the company.
Does the 6.2 million figure mean 6.2 million people?
No: those are raw rows. After deduplication, the hacker cites roughly 15,000 unique
accounts.
How was access allegedly obtained?
Per ZeroBytes: a public WordPress site, then an exposed ERP, then the production
database β not independently verified.
π Last checked: August 23, 2026. Verifiable
information to report: contact@egidio.app.
Cite this pageEgidio β The Threat Laboratory, "Declic Services: 6.2 million rows claimed, roughly 15,000 real accounts," egidio.app/en/laboratoire/declic-services-attack-chain-breach/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.