Overview
- Intermarché says its teams detected and blocked an intrusion that targeted its Drive service last week and that it has reported the incident to the CNIL and filed a complaint with the Paris prosecutor.
- The company has identified and emailed 287,605 Drive customers as affected so far out of about 2 million users, and investigators are continuing to search for any additional compromised accounts.
- Attackers accessed personal customer fields including names, dates of birth, billing and postal addresses, phone numbers, loyalty card numbers and some order details, according to Intermarché.
- Intermarché states that no banking data, passwords, email addresses or loyalty-account balances were taken and it is urging warned customers to ignore unsolicited links or requests and to verify communications through official channels.
- The breach was first flagged by the alert site French Breaches and, given the data exposed, security experts warn it could fuel targeted phishing and social-engineering scams that customers and regulators will be watching closely.