French home and garden chain Leroy Merlin has informed thousands of its customers in France that it has been the victim of a targeted cyberattack, which led to a data breach. The company, which operates in more than a dozen countries in Europe, South Africa and Brazil, employs 165,000 people and has an annual turnover of almost $10 billion, is now facing the consequences of a serious digital incident.

What data was exposed in the cyberattack?
According to the notification received by customers – which was posted on social media by user SaxX_– the breach concerns the French market. Among the data believed to have been leaked are:
- Full name
- Phone number
- E-mail address
- Mailing address
- Date of birth
- Information related to the rewards program
See also: Phoenix and Penn Universities Disclose Data Breach
Leroy Merlin confirmed that the attack targeted the company's information system, leading to unauthorized access to data. The message to customers states that, once the breach was detected, immediate measures were implemented to restrict access and prevent further leaks.
Importantly, the company clarified that no banking data or account, thus limiting the chances of direct financial fraud.
No signs of malicious use – but vigilance is needed
Although there is no indication so far that the stolen data has been used for malicious actions – such as posting on hacking forums or blackmail attempts – Leroy Merlin urges users to remain vigilant.
The history of such incidents has shown that even “simple” personal information can be the basis for social engineering attacks, phishing attempts or telephone scams. For this reason, the company provides customers with instructions on how to recognize deceptive emails and suspicious messages that may pretend to come from Leroy Merlin.
Those who notice unusual activity in their accounts or find problems with the loyalty program – such as unexpected redemption of points – are urged to contact the company immediately.
See also: Hybrid Phishing Attacks: Integration of Salty2FA and Tycoon2FA

Leroy Merlin's attitude and the unknown parameters
BleepingComputer confirmed the authenticity of the alert and requested additional information from Leroy Merlin, such as the total number of affected customers. However, there had been no official response by the time of publication.
Furthermore, no known ransomware group has claimed responsibility for the attack – an element that leaves open the possibility that this is a targeted attack with different motives or even a breach that is in the early stages of investigation.
What the attack means for the European retail space
The Leroy Merlin case adds to a growing list of cyberattacks targeting major retailers in Europe. Businesses that manage extensive customer networks and loyalty programs are attractive targets, as they collect large amounts of personal information – not necessarily financial, but enough for personalized fraud.
The need for enhanced security systems, frequent auditing and staff training is once again critical. At the same time, consumers are urged to adopt better protection practices, such as using different emails for important accounts and cross-checking any suspicious notifications.
See also: Coupang: Data breach affects 34 million customers
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The next step
While the Leroy Merlin investigation is still ongoing, the incident serves as a reminder that no organization – no matter how large – is immune to modern cyber threats. The coming days are expected to reveal more details about the origin and extent of the breach.
In the meantime, customers are urged to remain vigilant and monitor the company's announcements for any updates.
Source: www.bleepingcomputer.com
