Article Details

Original Article Text

Click to Toggle View

French DIY retail giant Leroy Merlin discloses a data breach. French home improvement and gardening retailer Leroy Merlin is notifying customers that their personal info has been compromised in a data breach. Leroy Merlin operates in multiple European countries as well as in South Africa and Brazil, employs 165,000 people, and has an annual revenue of $9.9 billion. The incident affects only customers in France, according to the notification published by an affected customer, and exposed the following data types: “A cyberattack recently targeted our information system, and some of your personal data may have leaked outside the company” (machine translated), reads the notification the company sent to affected customers. “As soon as the incident was detected, we took all necessary measures to block unauthorized access and contain the incident.” The company clarified that the exposed information does not include banking data or online account passwords. Also, the notice mentions that the stolen information has not been used in a malicious way, suggesting that it has not been leaked online or leveraged for extortion, but cautioned customers to remain vigilant of unsolicited communications. Customers receiving the notification are also provided with information on how to identify phishing messages attempting to impersonate the brand. If any anomaly is detected in customer account activity or trouble with redeeming loyalty discounts, customers are asked to report the activity directly to the company. BleepingComputer could confirm that the notification is genuine and has reached out to Leroy Merlin to request more details about the breach and how many customers are affected. We have not received a reply by publication time. At the time of writing, we did not see any ransomware group claiming the attack. Break down IAM silos like Bitpanda, KnowBe4, and PathAI Broken IAM isn't just an IT problem - the impact ripples across your whole business. This practical guide covers why traditional IAM practices fail to keep up with modern demands, examples of what "good" IAM looks like, and a simple checklist for building a scalable strategy.

Daily Brief Summary

DATA BREACH // Leroy Merlin Reports Data Breach Affecting French Customer Information

Leroy Merlin, a major DIY retailer, disclosed a data breach affecting its French customer base, compromising personal information but excluding banking data and passwords.

The breach impacts customers in France, with the company operating across Europe, South Africa, and Brazil, generating $9.9 billion in annual revenue.

Upon detection, Leroy Merlin implemented measures to block unauthorized access and contain the breach, minimizing potential damage.

The compromised data has not been used maliciously, and there is no evidence of it being leaked online or used for extortion.

Customers have been advised to remain vigilant against phishing attempts and report any suspicious account activity or issues with loyalty discounts.

BleepingComputer confirmed the authenticity of the notification and is seeking further details from Leroy Merlin about the breach's scope.

No ransomware group has claimed responsibility for the attack, and the situation remains under investigation.