← All datasets

boulanger.com

Sep 1, 2024

27,560,238
Records
2
Files
May 30, 2026
Added

In September 2024, French electronics retailer Boulanger suffered a data breach exposing over 27 million rows of customer data (approximately 13.8 million after deduplication), affecting nearly 5.4 million customers. The leaked data included full names, email addresses, phone numbers, physical addresses, zip codes, city, country, and geographic coordinates (latitude/longitude). Approximately 2.3 million unique email addresses were exposed. The data was published on BreachForums and has been indexed by Have I Been Pwned.

Data found in this dataset

EmailAddressCityCountryskipaddress2zipphonefullName

Search this dataset

Scoped to this dataset. Fill any combination — results match if any field hits.

Source files

Expand any file to inspect its column headers and the LLM's field-mapping reasoning, recorded during ingestion.

Boulanger__Info.txt
115 rows

File structure

Notes: Pre-LLM auto-detection: free-form text with visible emails / phones

Boulanger__data__boulanger.json
31 columns27,560,123 rows

File structure

Format: NDJSON

Source columnMapped fieldConfidenceLLM assessment
confirmation_codeskiphightransactional confirmation code; not PII
citycityhighcity names; breach context confirms cities were exposed
mobile_typeskiphighdevice type flag
team_idsskiphighinternal array of team assignments; not customer PII
extrasskiphighunstructured extra data field
external_idskiphighexternal system ID; numeric identifier
business_codeskiphighinternal business classification code
languageskiphighconsistently null; language preference metadata
merchant_idskiphighinternal merchant identifier
boroughskiphighconsistently null/empty; administrative subdivision
allow_sending_emailskiphighcommunication preference boolean; not PII
streetskiphighconsistently null; data appears in 'address' field instead
rankskiphighconsistently null; internal ranking field
idskiphighauto-increment numeric ID
statecountryhighcountry code (FRA, FR); breach context confirms country data exposed
client_versionskiphighsoftware version metadata
client_nameskiphighsoftware/client identifier; not personal PII
latskiphighgeographic coordinate (latitude); not PII field type
emailemailhighemail addresses; breach context confirms 2.3M unique emails exposed
imageskiphighinternal asset path reference
addressaddress1highstreet addresses; mailing/residential addresses per breach context
lngskiphighgeographic coordinate (longitude); not PII field type
kindskiphighconsistently null; internal classification
customer_notesskiphighinternal notes array; not customer PII
address_second_lineaddress2highsecondary address info (apt numbers, building details)
zipcodeziphighpostal codes; breach context confirms zip codes were exposed
has_parking_areaskiphighboolean property flag; not PII
phonephonehighphone numbers in +33 format; breach context confirms phone numbers exposed
districtskiphighconsistently null; administrative subdivision
namefullNamehighcontains full names with honorific prefixes (M., MME) and surnames
allow_sending_smsskiphighcommunication preference boolean; not PII

Notes: Boulanger French electronics retailer breach (Sept 2024). Data includes personal customer records with full names, emails, phone numbers, mailing addresses, zip codes, cities, and country (France). Some records are business/store locations (NAVETTE entries, Boulanger Chambray, etc.) rather than individual customers; these have null phone/email but are included in the export. The 'state' field consistently contains 'FRA' or 'FR' country codes, not region/state data. Geographic coordinates (lat/lng) are present but map to skip. Address data confirmed as residential/mailing addresses per breach description.

boulanger.com. Shadow Identity