Egidio
Case file Β· August 21, 2026

WiziShop/Dropizi/Evolup: invoices since 2009 exposed, fixed the same day

WiziShop confirmed an incident exposing all invoices issued since 2009 on its WiziShop, Dropizi and Evolup services. The vulnerability was fixed the same day it was discovered; no bank data or password is affected.

⚠️ Confirmed by WiziShop itself. The company proactively notified its clients and specified the exact scope of affected data, which sets this case file apart from unverified claims.

The numbers

2009
Year since which all issued invoices are affected β€” more than 15 years of history.
WiziShop client notice, FrenchBreaches, August 19, 2026.
3
Services affected: WiziShop, Dropizi and Evolup.
WiziShop client notice.
0 days
Time to fix: the vulnerability was corrected the same day it was discovered, August 17, 2026.
WiziShop client notice.
0
Bank details, login credentials or password affected, according to WiziShop.
WiziShop client notice.

Timeline

CONFIRMED
August 17, 2026
WiziShop is alerted to a security incident allowing a malicious third party to download a significant volume of invoices related to its WiziShop, Dropizi and Evolup services. The vulnerability is fixed the same day.
CONFIRMED
Follow-up
The company notifies its clients: all invoices issued since 2009 are affected (business name, postal address, client number, billing references and dates, amounts). Bank details, login credentials, passwords, and shop data (catalogs, orders) are not affected.

⏱️Fifteen years of history, a narrow scope

This case file illustrates a contrast: the time depth is unusual β€” fifteen years of invoices β€” but the type of data exposed remains narrow, billing metadata rather than banking credentials. The same-day fix also contrasts with cases where a company only reacts days or weeks after a public claim.

What it changes for you

If you used WiziShop, Dropizi or Evolup to build an online shop since 2009, an invoice in your name may have leaked β€” with your postal address and client number. The main risk is a phishing email citing a real invoice number to appear legitimate. See From Leak to Scam.

πŸ”’ Be wary of any email claiming to be from WiziShop, Dropizi or Evolup asking you to update your bank details: that data type was not affected by this incident, so such a message would be suspicious.

Frequently asked questions

Is the WiziShop incident confirmed?

Yes, by the company itself, which notified its clients directly.

What data is affected?

All invoices since 2009: business name, address, client number, billing references, amounts.

Was the flaw fixed quickly?

Yes, the same day it was discovered, August 17, 2026.

πŸ“Œ Last checked: August 21, 2026. Verifiable information to report: contact@egidio.app.

Related reading

Cite this page Egidio β€” The Threat Laboratory, "WiziShop/Dropizi/Evolup: invoices since 2009 exposed, fixed the same day," egidio.app/en/laboratoire/wizishop-dropizi-invoice-breach/. Licensed CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.