Summary
- The incident affected 287,605 users of Intermarché’s online click-and-collect service.
- Exposed records included names, addresses, telephone numbers, dates of birth, loyalty identifiers, and some order information.
- Banking information, passwords, email addresses, and loyalty balances were not involved, according to the retailer.
Unauthorised access to Intermarché’s Drive click-and-collect service has exposed personal information belonging to 287,605 customers.
The affected records included names, postal addresses, telephone numbers, dates of birth, loyalty-card numbers, and details connected to some orders. Intermarché said banking information, account passwords, email addresses, and loyalty balances were not involved.
The French supermarket operator identified the affected population from approximately two million customers using its Drive service and contacted those believed to be involved. Its investigation remains open, meaning the final scope could change if additional compromised records are identified.
Groupement Les Mousquetaires, which operates Intermarché, notified France’s data protection authority, the Commission nationale de l’informatique et des libertés, and filed a complaint with the Paris public prosecutor.
The company has not disclosed how the intruder obtained access, how long the activity continued, or whether a software vulnerability, customer account, employee identity, or connected provider was involved. No attacker has been publicly identified.
The excluded data categories reduce some immediate financial and account-takeover risks. An attacker cannot use the exposed records alone to obtain a customer’s Intermarché password or payment-card number.
The remaining information can still support credible impersonation. A message that includes a customer’s address, loyalty number, recent order, or preferred collection location may appear substantially more convincing than generic phishing. Telephone numbers also enable follow-up through calls or messaging services.
Dates of birth and home addresses are persistent identity attributes that cannot be rotated like passwords. Their value can increase when combined with information from other breaches, public records, or social networks.
Order histories may also reveal patterns beyond the individual transaction. Regular collection times, household products, dietary items, or high-value purchases could help an attacker tailor fraud attempts, although Intermarché has not stated that every affected record contained the same depth of order information.
The incident illustrates the amount of information required to operate click-and-collect services. A platform must connect customer identities, shops, stock, loyalty accounts, orders, collection arrangements, and fulfilment records. That integration creates a larger pool of linked data than a conventional in-store purchase.
Under the General Data Protection Regulation, the operator must document the incident, assess the likely consequences for affected people, notify the regulator where required, and communicate directly when the risk reaches the relevant threshold. The combination of exposed fields, rather than the presence or absence of one category, will inform that assessment.
Intermarché has provided a precise initial count and described which information was and was not involved. The access method, duration, and evidence of subsequent misuse remain undisclosed.



