Description

Leroy Merlin, a major European home improvement retailer, has disclosed a data breach affecting customers in France. According to notifications shared online, attackers gained unauthorized access to parts of the company’s information system and exposed sensitive personal details. The compromised data includes full names, phone numbers, email addresses, postal addresses, dates of birth, and loyalty program information. Leroy Merlin clarified that no banking data or account passwords were accessed. The company states it immediately contained the breach after discovery and blocked further unauthorized access. This incident highlights the ongoing threat of data theft targeting large retail businesses with extensive customer databases. Although investigators have not identified any malicious use of the stolen data so far, exposed personal information can facilitate phishing, identity fraud, and targeted social engineering attacks in the future. Leroy Merlin has warned users to stay alert for suspicious emails or messages impersonating the brand, as attackers commonly exploit breached data to craft convincing scams. No ransomware group has taken responsibility for the attack, and the total number of affected customers remains undisclosed. To reduce risk, Leroy Merlin has advised customers to monitor their accounts and loyalty benefits closely and report any irregularities. Organizations facing similar threats should ensure strong access controls, continuous monitoring, and rapid incident response procedures. Customers are encouraged to verify the authenticity of communications, avoid clicking unknown links, and update passwords regularly. Maintaining strong cybersecurity hygiene such as MFA, up-to-date systems, and awareness of phishing red flags remains critical to mitigating the impact of data breaches.