-
A cyberattack on the Drive grocery service of Intermarché has exposed the personal details of 287,605 customers out of two million total users.
-
Stolen data includes names, phone numbers, delivery addresses, birth dates, and order numbers, but no banking details or passwords were compromised.
-
The retailer notified data regulator CNIL and filed a criminal complaint with the office of Paris prosecutor.
Recently, the French retail company Intermarché was the victim of a significant cyberattack that compromised the data of its customers from its online grocery delivery service.
The cyber attackers were able to get into the internal system of Intermarché that it uses for managing drive orders for millions of customers.
The parent company of Intermarché, Groupement Les Mousquetaires, has confirmed the security breach after detecting unusual activities on its network.
The security incident affects nearly 300,000 customers out of the two million registered drive users. Company security teams contained the threat quickly and notified local law enforcement authorities. Management also warned affected shoppers to watch out for potential phishing scams.
Exposed Customer Information and Safe Financial Records
The hackers breached database files that store personal buyer details. Stolen records include full customer names, telephone contacts, home billing addresses, and birth dates. The leaked files also display loyalty card numbers, order reference codes, and total purchase amounts.
However, the company confirmed that cybercriminals missed critical personal records. The stolen database contained no passwords, banking records, credit card numbers, or secret login codes.
In addition, the attackers failed to access email addresses or loyalty account reward balances. Shoppers did not lose any saved monetary funds from their digital reward wallets.
The breach specifically hit the popular online order pick-up service of the supermarket. Millions of French families use this drive service to buy weekly groceries online.
Customers pick up their pre-packed grocery boxes at local storefront stations. Storing large volumes of personal delivery details makes these store systems attractive targets for internet thieves.
According to the experts in cybersecurity, scammers are using stolen information to create sophisticated scam messages. Criminals merge such details to set up a convincing scheme for the unsuspecting citizens.
Also, these fake messages often appear to come from the real delivery drivers or managers. Consequently, consumers must remain extra careful when answering unexpected calls or opening text links.
The supermarket sent individual warning letters to 287,605 identified victims. The warning message urges users to spot suspicious communications from unknown sources.
Legal Notifications and Official Security Actions
Company technicians shut down the unauthorized access points immediately after discovering the breach. Internal safety teams isolated affected servers to protect neighboring computer networks. Company managers also launched deep forensic investigations to trace how the intruders entered the system.
French laws state that businesses must notify the government regulatory agencies of any violations of personal data. Consequently, the supermarket has sent the information to the French oversight institution, known as Commission Nationale de l’Informatique et des Libertés, CNIL.
The agency monitors corporate compliance under European data privacy rules. Officials review whether the supermarket maintained adequate security controls to protect citizen files.
The retail parent group also filed a formal legal complaint with French judicial authorities. Lawyers submitted the official case file to the office of Paris prosecutor. State police investigators are now working to identify the illegal hacker group behind the intrusion.
In addition, European regulators are putting in place some tough rules on how to handle data, via the European Data Protection Board system. Companies that do not do enough to keep user data secure will find themselves subject to heavy fines. Business leaders must prove that they patched software vulnerabilities and updated firewall defenses.
System administrators changed internal access keys to block stolen administrative credentials. The grocery chain promised to strengthen infrastructure monitoring to stop future digital trespassers.
Rising Cyber Threats Across European Retail Chains
This supermarket hack reflects a growing wave of cybercrime hitting the European retail sector. Cybercriminals target big store chains because retail databases hold valuable consumer information.
The broader security concerns across Europe have led governments to explore homegrown messaging solutions, with several nations moving to build their own encrypted communication apps. Recent months saw similar intrusion attempts against electronic sellers and cultural supply stores across France.
Meanwhile, threat actors post stolen customer databases on underground dark web forums. Other criminal groups purchase these contact lists to launch automated phone scams and identity theft tricks. Online grocery portals remain popular targets because millions of users share home addresses daily.
Retail leaders are spending more money to upgrade their cybersecurity tools. They install advanced threat detection software and train employees to spot suspicious login requests. Modern grocery operators must continuously review their data backup tools and access permissions.
Consumers can also protect themselves by taking simple safety steps; they should avoid sharing unnecessary personal details on public store forms.
Changing online passwords regularly helps keep personal accounts safe from opportunistic hackers. Users should also monitor their bank statements to detect any strange activity early.
The supermarket chain is actively monitoring its information systems for any possible threat signals. The leadership of the company issued an apology statement to its customers and promised to take their safety as its top priority. State authorities will continue tracking the stolen database files to stop further distribution online.