HomeSecurityleroymerlin.gr: Down for a week — Technical issue or something more serious?

leroymerlin.gr: Down for a week — Technical issue or something more serious?

The website www.leroymerlin.gr has been in a “temporary unavailability” state since last week , as the company itself states in an information message that appears on the homepage, while this situation has lasted an unusually long time without a clear explanation for the cause. The Greek version of Leroy Merlin , one of the largest DIY and home improvement chains in Europe, cites a “technical issue” as the cause — although Greek users express concern about the duration of the incident and the possible real conditions.

Leroy Merlin Greece website down screenshot

According to an anonymous tip that reached the secure reporting platform report.secnews.gr, the reasons behind the outage could be more serious than the company officially states. There is, so far, no official confirmation of a cyberattack from Leroy Merlin Greece or from the competent authorities. The editorial team of SecNews has been following the case from the beginning and will update with new information as soon as it officially emerges.

See also: Leroy Merlin reveals data breach (December 2025)

What does the official message on leroymerlin.gr say?

The message displayed on the home page is absolutely clear in terms of diagnosis, but without details: “Our website is temporarily unavailable. We are currently experiencing a technical issue that is affecting the operation of our website. Access remains temporarily unavailable, while our teams are working intensively to restore its operation.” The company refers customers to physical stores and provides the central service numbers — 21 1120 3040 for Greece and 22 473400 for Cyprus.

Although the term “technical issue” covers a wide range of situations — from server failure to system replacement or security incident — the duration is the distinguishing factor. Users on the Greek forum Insomnia.gr report that since last week they have been trying to place orders, testing from three different prefectures and multiple devices, but the same blocking page consistently appears.

online store out of service incident investigation
The prolonged outage of leroymerlin.gr raises questions about the real cause and the possibility of a security incident.

Possible cyberattack: What is likely, what suspicions does the situation raise?

The SecNews technical team points out that a week of downtime is difficult to explain based on typical technical problems, especially for a multinational company with a mature IT infrastructure. The most common causes of such a prolonged outage include: a ransomware that has encrypted databases or ordering systems, a supply chain attack on a cloud or SaaS provider, a massive potential customer data leak with a preventive shutdown of the infrastructure, or a critical vulnerability in an ecommerce platform that requires extensive restructuring.

Another questionable element: Leroy Merlin already has a history of security incidents. In addition to the December 2025 data breach covered by SecNews, in June 2026 the Cybersecurity Agency of Catalonia announced a separate security incident on Leroy Merlin’s Hogami platform, which exposed personal customer information (names, emails, phone numbers, addresses). The company clarified at the time that no passwords, credentials or banking details were affected, but warned of possible phishing attacks against its customers.

What should customers in Greece do?

The editorial team of SecNews recommends specific precautionary measures for all Leroy Merlin Greece customers who have an active account on the platform. First, be especially careful with incoming emails, SMS or phone calls impersonating Leroy Merlin — the company's historical incidents show that any malfunction tends to be accompanied by an increase in phishing attempts that exploit the noise to convince victims to provide information.

Second, if the same password is used on multiple platforms, customers should change it immediately across all services — this is basic security hygiene regardless of whether it’s an attack or a technical issue. Third, they should not make payments through any alternative “temporary” links circulating on social media — only through official phone lines or physical stores.

See also: Europol: "Hit" on online fraud ring with victims in Greece

The role of report.secnews.gr and the obligation to inform

SecNews supports the secure transmission of information of public interest through the anonymous reporting platform report.secnews.gr. Whistleblowers within businesses, organizations or public bodies who observe security incidents, personal data breaches, or worrying practices can communicate with the editorial team without any trace of identity, as the platform does not record IP, metadata or login details.

At the same time, according to the General Data Protection Regulation (GDPR), companies that suffer a personal data breach are required to inform the Hellenic Data Protection Authority (HDPA) within 72 hours of becoming aware of the incident, if there is a risk to the rights of the subjects. Leroy Merlin itself, as a French company with a Greek subsidiary, is also required to comply with the CNIL obligations and the European regulatory framework.

Next steps and waiting for official information

The SecNews editorial team is monitoring the development and awaits an official announcement from Leroy Merlin Greece on the cause of the outage, the estimated restoration date, and whether customer data was affected. We will also monitor any announcements from the Cybercrime Prosecution (telephone 11188) and the Hellenic Anti-Corruption Commission, in case there is an official notification of a security incident.

The article will be updated with new information. Leroy Merlin customers who notice suspicious activity in their accounts or receive suspicious emails impersonating the company can report the incident to the Cybercrime Prosecution or the Anti-Corruption Commission. Whistleblowers with additional information can contact us anonymously via the report.secnews.gr.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS