Alleged Breach of Smarteez Exposes Full Production Database for L’Oreal Morocco Including 296 Pharmacies, 361K Sales Records, OAuth Secrets, and Competitive Intelligence Across Four L’Oreal Brands

Alleged Breach of Smarteez Exposes Full Production Database for L’Oreal Morocco Including 296 Pharmacies, 361K Sales Records, OAuth Secrets, and Competitive Intelligence Across Four L’Oreal Brands
Threat actor xNov leaked the full production database of Smarteez, the digital factory operating for L’Oreal Morocco, exposing operational data for La Roche-Posay, Vichy, CeraVe, and Dercos from mid-2023 to early 2026. The public leak includes 296 pharmacies, over 361,000 sales analytics records, OAuth2 client IDs with 128-character plaintext client secrets, PBKDF2-hashed user accounts, extensive competitive intelligence media, admin audit logs, and system configuration details. #xNov #Smarteez

Keypoints

  • xNov publicly leaked Smarteez’s complete production database used by L’Oreal Morocco.
  • The breach affects four brands β€” La Roche-Posay, Vichy, CeraVe, and Dercos β€” spanning mid-2023 to early 2026.
  • Exposed data includes 296 pharmacies with full location and territory details and 361,000+ sales analytics records.
  • Critical credentials and config data leaked: 22 OAuth2 apps with plaintext 128-character client secrets, 26 PBKDF2-hashed user accounts, and 519 Django session records.
  • The leak contains over 1 million merchandising and competitive intelligence media files plus a 4,504-entry admin action log and APK download URL.
DarkWebInformer.com Providing intel from some of the darkest places on the Dark Web & Clearnet. Breaches, Darknet Markets, Ransomware, Threat Alerts, & more!

Read More: https://darkwebinformer.com/alleged-breach-of-smarteez-exposes-full-production-database-for-loreal-morocco-including-296-pharmacies-361k-sales-records-oauth-secrets-and-competitive-intelligence-across-four-loreal-/