Search TorWire

Find cybersecurity guides and research articles

Home > News > Deep Web > Hackers Claim Sale of 1.39 Million Intermarché Customer Records on Cybercrime Forum

Hackers Claim Sale of 1.39 Million Intermarché Customer Records on Cybercrime Forum

By: Jordan Vector Cybersecurity Expert

Last updated: August 6, 2026

Human Written
Hackers Claim Sale of 1.39 Million Intermarché Customer Records on Cybercrime Forum
  • A threat actor claims to have breached Intermarché and is selling over a million records of customers on a cybercrime forum, though the authenticity remains unverified.

  • The seller also claims to have accessed an RDP server and multiple internal systems within the network of the supermarket chain, including internal server and tool information.

  • Intermarché has not publicly confirmed the breach, but security experts urge caution until official verification or technical validation emerges.

A cybercriminal has posted their advertisement in a dark web forum, with claims to have hacked into Intermarché, a big French supermarket. The hacker has put on the market a so-called client database containing 1,393,807 entries.

The alleged data includes customer information and drive service records. The seller also claims to have accessed internal server and tool information.

The threat actor further claims they gained entry to an RDP server inside the network of the company. This would enable them to access several internal systems.

However, it is unclear whether the claims are genuine as there has been no confirmation regarding the event or the database.

What the Alleged Data Contains

According to the forum listing, the stolen data includes customer information. This likely means names, addresses, and contact details. The seller also claims to have drive service records from the online ordering system of Intermarché. These records could contain order histories and delivery information.

The threat actor says they accessed internal server information. This might include system configurations and network details. They also claim to have internal tool information used by company staff. Such data could help other attackers plan future intrusions.

The seller claims that they hacked an RDP server in the network of the company. RDP or Remote Desktop Protocol is a method used for connecting remotely to computers. Taking control of such servers represents a grave risk in terms of security. This enables criminals to gain entry into the network of a company.

Nonetheless, Intermarché has not confirmed any occurrence of a breach yet. No statements have come from the responsible French officials either. Experts recommend practicing caution until something is confirmed officially.

Details About the Potential Breach

The seller claims that they obtained the information via unauthorized access. They reportedly hacked an RDP server in the network of the company. This suggests that the attackers used stolen credentials or some vulnerabilities connected to remote access technology.

The post on the forum does not provide any samples of the data, and the claims of the seller have no proof of confirmation yet. Therefore, it is difficult to ascertain whether the data claimed by the seller actually exists. Security experts suggest being cautious when dealing with claims of this kind as long as no evidence supports them.

The hacker intends to sell the stolen data through Telegram. This method of distribution matches previous dark web sales. The encrypted messaging apps serve as means to spread stolen information, making it impossible for the police to locate and ensure the prosecution of offenders.

Impact on Intermarché Customers

If the allegations are valid, the breach may affect around 1.4 million customers. These customers have a high risk of identity theft and attacks from phishing. Cybercriminals may exploit personal information by committing more fraud based on such personal information.

It is common for attackers to mix data from one breach with information they harvested from other breaches. Doing so allows to develop the complete profile for the subsequent targeted attack.

Thus, customers need to be careful with suspicious email and messages they receive, they should also actively monitor their accounts for any unauthorized transactions.

In addition, the breach can damage the reputation of Intermarché and make consumers question their ability to ensure the safety of information about them. Also, due to privacy laws in force in France, the company can face legal consequences.

The episode continues the series of attacks on retail companies in France. Cybercriminals often attack companies that possess large amounts of information about customers for their own profit. The personal information of millions of consumers has significant market value.

Growing Threat to Retailers

The alleged Intermarché breach highlights a growing threat to retailers; French supermarkets have also become attractive targets for cybercriminals. These companies hold large databases of customer information. They also process millions of transactions each day.

Other French retailers and even agencies previously endured the same fate. Two years ago, a breach hit another French supermarket, Auchan, resulting in about 500,000 of impacted consumers. This July, Intermarché announced that a breach may have impacted up to 2 million of its customers. The retailer informed the Parisien about a separate incident involving customer records.

That July breach, which exposed the data of 287,605 Drive customers, was confirmed by the retailer and notified to France’s CNIL data protection authority.

Similarly, a French government agency, ANT, suffered an attack in June, which compromised personal records of about 19 million French citizens. This information consisted of full names, e-mail addresses, home addresses, phone numbers, birth data and much more. Bad actors can use this data for the purpose of targeting victims for marketing or criminal activities.

Response and Prevention

Intermarché has not yet made any official comment regarding the alleged incident. The company has a data protection personnel, who takes care of such matters. Retail companies in France have the obligation to inform the CNIL, which is the French data protection authority, about any data breaches.

In this regard, firms in the retail industry must increase their cyber defense measures. This includes the use of multi-factor authentication for remote access and the conducting of security audits and vulnerability assessments. Also, training employees to spot phishing attempts is crucial.

Share this article

About the Author

Jordan Vector

Jordan Vector

Cybersecurity Expert

Jordan is a security researcher and advocate who focuses on making privacy practical. Whether he's explaining how to harden a browser or reporting on the latest surveillance disclosures, his goal is to equip readers with knowledge they can use immediately. Jordan believes that true security begins with understanding the digital landscape.

Comments (0)

No comments.