Tech News

LDLC Confirms Data Breach: Customer Personal Information Accessed

October 3, 2026Diego Herrera2 мин

French online retailer LDLC has reported a cybersecurity incident. Unauthorized access to one of its systems allowed cybercriminals to view customer personal data. This includes names, addresses, phone numbers, and account details. LDLC assures that banking information and passwords were not compromised.

The company is notifying affected customers via email. The exposed data includes first and last names, postal and email addresses, landline and mobile phone numbers, and potentially fax numbers if provided. User language preferences, individual or business account status, and "technical client codes"—internal LDLC identifiers—were also accessed.

Customer titles, such as "Doctor" or "Master," may have also been revealed, potentially indicating professions like doctors or lawyers. Account creation dates and last login dates were also part of the accessed information, offering insight into customer tenure and site engagement. Such details are valuable for fraudsters aiming to craft convincing phishing attempts.

LDLC states that bank account details (RIB), credit card numbers, login credentials, and passwords remained secure. The company has isolated the affected system, reviewed its access protocols, and notified the French data protection authority, CNIL.

As LDLC acknowledges, the primary risk from data leaks often emerges later. Fraudsters can use the collected personal information to create fake communications—like messages about blocked parcels or pending refunds—that appear legitimate by addressing the recipient by name, referencing their customer history, and using their real phone number. This is the core mechanism of phishing: impersonating a trusted entity to extract sensitive information.

LDLC emphasizes that its teams will never request passwords, banking details, or changes to bank information via email, SMS, or phone. Customers are advised to verify sender identities and link destinations before clicking on any communication. For suspicious calls, customers should not proceed and should instead contact LDLC through its official channels. Guidance on identifying malicious messages is available on the public website Cybermalveillance.gouv.fr. Business customers, whose status was among the exposed data, should be particularly vigilant regarding any requests for bank modification.

The company has not disclosed the number of affected customers, the date of the intrusion, or the method used by the attackers. It remains unclear whether the data was merely viewed or fully copied, and there is no confirmation of a complete database extraction. This incident echoes past security issues for LDLC, including a ransomware attack in late 2021 and previous customer data leaks in early and December 2024.