Leroy Merlin, a major European home improvement retailer, has disclosed a data breach affecting customers in France. According to notifications shared online, attackers gained unauthorized access to parts of the company’s information system and exposed sensitive personal details. The compromised data includes full names, phone numbers, email addresses, postal addresses, dates of birth, and loyalty program information. Leroy Merlin clarified that no banking data or account passwords were accessed. The company states it immediately contained the breach after discovery and blocked further unauthorized access. This incident highlights the ongoing threat of data theft targeting large retail businesses with extensive customer databases. Although investigators have not identified any malicious use of the stolen data so far, exposed personal information can facilitate phishing, identity fraud, and targeted social engineering attacks in the future. Leroy Merlin has warned users to stay alert for suspicious emails or messages impersonating the brand, as attackers commonly exploit breached data to craft convincing scams. No ransomware group has taken responsibility for the attack, and the total number of affected customers remains undisclosed. To reduce risk, Leroy Merlin has advised customers to monitor their accounts and loyalty benefits closely and report any irregularities. Organizations facing similar threats should ensure strong access controls, continuous monitoring, and rapid incident response procedures. Customers are encouraged to verify the authenticity of communications, avoid clicking unknown links, and update passwords regularly. Maintaining strong cybersecurity hygiene such as MFA, up-to-date systems, and awareness of phishing red flags remains critical to mitigating the impact of data breaches.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2024-21182, a critical vulnerability affecting Oracle WebLogic Server, to its Known Exploited Vulnera...
Dashlane has revealed that it recently detected and mitigated a targeted brute-force attack aimed at a limited number of user accounts. The incident triggered the company's aut...
Google has disclosed CVE-2025-48595, a critical Android zero-day vulnerability affecting the Android Framework component. The flaw enables remote privilege escalation without requi...