Intermarché Data Breach: 300,000 Customers Hit by Cyberattack

Another week, another major French retailer added to the growing list of cyberattack victims. On August 3, 2026, the Groupement Mousquetaires, the parent company behind Intermarché, confirmed that its online grocery service, Drive Intermarché, had suffered a cyberattack that exposed...

Intermarché data breach affecting 300,000 customers, illustrated with a supermarket, cybersecurity shield, warning alert, and digital network.

Another week, another major French retailer added to the growing list of cyberattack victims. On August 3, 2026, the Groupement Mousquetaires, the parent company behind Intermarché, confirmed that its online grocery service, Drive Intermarché, had suffered a cyberattack that exposed the personal data of nearly 300,000 customers.

The incident is a reminder that even long-established retail brands with millions of loyal shoppers are not immune to cyber threats. For anyone who has ever placed a click-and-collect order through Intermarché's Drive service, or who simply follows how European retailers are handling data protection, this breach is worth understanding in detail.

What Happened

According to Intermarché, the cyberattack took place during the last week of July 2026 and targeted the customer files linked to its Drive service, the platform customers use for online grocery orders and click-and-collect purchases. The breach was first reported by the cybersecurity outlet French Breaches before Intermarché confirmed the incident to French media.

The company described the event as unauthorized access to certain confidential customer data. As of the disclosure, 287,605 Drive customers, out of a Drive customer base of roughly two million, had been identified as affected and notified directly. Intermarché also said additional investigation was underway to determine whether more accounts had been compromised, so the final number could still grow.

What Data Was Exposed

Data breach severity usually comes down to one question: what exactly did the attackers get their hands on? Intermarché has been fairly transparent about the scope of the exposure, and the picture is mixed. Sensitive personal identifiers were compromised, but the company says financial data was not touched.

Data That Was Exposed Data That Was Not Accessed
Full names Banking details
Phone numbers Loyalty point balances
Postal addresses Account passwords
Dates of birth Email addresses
Loyalty card numbers  
Partial online order history  

On paper, this looks like it could have been worse. No payment cards, no bank account numbers, no passwords. But security professionals tend to push back on the idea that a breach without financial data is a "minor" breach. Names, phone numbers, birthdates, and order history are exactly the raw materials attackers need to build convincing phishing and impersonation campaigns. That combination of details is often more dangerous in the wrong hands than a stolen card number, because a card can be cancelled in minutes while a person's identity profile cannot.

How Intermarché Responded

To its credit, Intermarché moved relatively quickly once the incident was confirmed. The group notified the CNIL, France's national data protection authority, in line with its obligations under the GDPR's 72-hour breach notification rule. It also filed a formal complaint with the Paris public prosecutor's office, opening the door to a criminal investigation alongside the regulatory review.

Affected customers were contacted directly by email or letter and advised to stay alert for phishing attempts. Intermarché specifically warned that the stolen data could be used to make scam calls, texts, or emails appear more credible, since a message that references your real name, address, and recent order history is far more convincing than a generic scam attempt.

This is a fairly standard playbook for post-breach communication: notify the regulator, notify the customers, and warn people about downstream social engineering risks. Whether it goes far enough, particularly around monitoring for a possible increase in the affected customer count, is something regulators and privacy advocates will likely continue to scrutinize as the investigation develops.

Why This Keeps Happening to French Retailers

Intermarché is not an isolated case. France's retail and telecom sectors have faced a wave of high-profile breaches over the past couple of years, and each one tends to follow a similar pattern: a large customer database, a third-party service or legacy system as the point of entry, and personal data ending up in the hands of attackers who use it for phishing rather than direct financial theft.

Retailers are attractive targets for a simple reason. They sit on enormous stores of customer data collected through loyalty programs, online ordering platforms, and click-and-collect services, yet many of them were not originally built as data-security-first organizations. E-commerce and loyalty systems were often bolted onto older retail infrastructure over time, which creates exactly the kind of fragmented environment that attackers look for.

For a closer look at how this specific incident unfolded, France Info's coverage of the Intermarché breach includes the group's own statement and further detail on the ongoing investigation.

What Affected Customers Should Do Now

If you shop through Drive Intermarché, or you have simply received a notification about this breach, a few practical steps go a long way toward reducing your exposure.

Action Why It Matters
Treat unexpected calls or texts with caution Scammers may reference your real name, address, or order history to sound legitimate. A business that already has your data will rarely ask you to confirm it over the phone.
Never click links in unsolicited messages Go directly to the official Intermarché website or app instead of clicking a link sent by email, text, or messaging app.
Watch for identity-related fraud Because dates of birth were exposed, keep an eye out for unfamiliar accounts, credit applications, or subscription sign-ups in your name.
Update passwords out of caution Passwords were not confirmed as exposed, but changing your Intermarché password, and any other account where you reuse it, is a low-effort precaution.
Report suspicious activity If you receive a scam attempt referencing this breach, report it to Intermarché and, in France, to the platform Cybermalveillance.gouv.fr.

The Bigger Lesson for Businesses

Beyond the immediate impact on Intermarché's customers, this incident is a useful case study for any organization that stores customer data, which today is essentially every organization. A few takeaways stand out.

First, breach notification speed matters. Intermarché notified the CNIL and reached out to customers within a short window of discovering the incident, which is exactly what GDPR expects and what limits reputational damage. Organizations that delay disclosure, or try to downplay the scope of an incident, tend to face far harsher scrutiny once the full picture becomes public.

Second, "no financial data was accessed" is not the same as "no harm was done." Names, phone numbers, and order history are enough to power convincing social engineering attacks, and businesses need to communicate that risk clearly to customers rather than framing a breach as low severity just because payment details were untouched.

Third, most breaches like this one trace back to gaps that are entirely preventable with the right combination of employee awareness and a tested incident response plan. Attackers frequently succeed not because of some unbreakable technical exploit, but because of a weak point in process, whether that is a phishing email opened by an employee, a misconfigured system, or a slow response once suspicious activity is first detected.

This is exactly where structured training makes a measurable difference. Teams that understand how phishing and social engineering attacks actually work are far less likely to be the entry point for an attacker. And organizations with a rehearsed incident response plan can contain a breach, notify regulators, and communicate with customers in hours rather than days, which directly limits the damage.

If your organization wants to reduce the human-error risk that sits behind most breaches like this one, our Cyber Security Awareness Training course walks employees through exactly the kind of phishing and social engineering tactics that follow a data breach of this scale. And if you want your team prepared to respond the moment an incident is detected, rather than scrambling to figure out next steps, our Cybersecurity Incident Response Training covers the practical playbook, from containment to regulatory notification, that separates a well-handled breach from a reputational crisis.

★ Free PDF Certificate Included

Strengthen Your Incident Response

Prepare your team to detect, assess, contain and respond to cybersecurity incidents effectively. Build a structured response process, clarify responsibilities and reduce the operational and regulatory impact of cyberattacks. Earn a recognized PDF certificate — free with the course. Self-paced, role-ready, and built to make you hireable.

Learn More →

Final Thoughts

The Intermarché breach will likely fade from headlines within a week or two, as these stories usually do. But for the 287,605 people already notified, and potentially more once the investigation concludes, the risk of targeted phishing attempts is far from over. And for every business watching from the sidelines, the real takeaway is not about Intermarché specifically. It is about how quickly any organization holding customer data can find itself in the same position, and how much of that risk comes down to preparation rather than luck.

Data breaches are no longer a rare, one-off crisis. They are a recurring risk that every organization needs to plan for, train for, and be ready to respond to. Staying informed about incidents like this one is a good first step. Building the internal awareness and response capability to prevent your organization from becoming the next headline is the step that actually matters.

You can find more on cybersecurity and compliance on our blog.

Frequently Asked Questions

Intermarché's parent company, Groupement Mousquetaires, confirmed a cyberattack in late July 2026 that gave unauthorized access to customer files linked to its Drive click-and-collect service. The company detected the intrusion, cut off access, secured its systems, and notified both the CNIL and the Paris prosecutor's office.

As of the disclosure, 287,605 Drive customers had been confirmed as affected, out of a Drive customer base of roughly two million. Intermarché noted that its investigation was still ongoing, so the final number could increase.

Exposed data included full names, phone numbers, postal addresses, dates of birth, loyalty card numbers, and partial online order details such as order numbers and amounts. Intermarché has not disclosed the identity of the attackers or whether any group has claimed responsibility.

No. Intermarché has stated that no banking details, passwords, email addresses, loyalty point balances, or product-level order details were accessed. The exposure was limited to identity and contact information.

Intermarché is contacting confirmed affected customers directly by email or letter. If you use Drive Intermarché and have not received a notification, it does not automatically guarantee your data was untouched, since the investigation is still active. When in doubt, check your account activity and treat any unexpected message referencing your Intermarché order history with caution.

Be cautious of unexpected calls, texts, or emails referencing your name, address, or recent orders. Avoid clicking links in unsolicited messages and go directly to the official Intermarché site or app instead. Update your password as a precaution, especially if you reuse it elsewhere, and monitor for any unfamiliar accounts or sign-ups made in your name.

Intermarché says the unauthorized access was interrupted as soon as it was detected and that the affected systems have since been secured. As with any breach, ongoing vigilance from customers is still recommended while the investigation continues.

The CNIL is France's national data protection authority. Under the GDPR, organizations must notify the CNIL within 72 hours of becoming aware of a personal data breach. Intermarché's notification to the CNIL, alongside its complaint to the Paris prosecutor's office, is part of this legal obligation.

Retailers hold large volumes of customer data through loyalty programs and online ordering platforms, often built on top of older systems that were not originally designed with data security as a priority. That combination of scale and fragmented infrastructure makes them attractive targets. Intermarché joins a growing list of French companies that have faced similar incidents in recent years.

Most breaches trace back to a preventable gap, whether that is a phishing email opened by an employee or a slow response once suspicious activity is detected. Training staff to recognize social engineering and having a tested incident response plan in place are two of the most effective ways to reduce that risk. Our full range of compliance and cybersecurity courses covers both, from employee awareness through to incident response and regulatory readiness.

We cover major cybersecurity incidents and compliance developments as they happen on ourblog, including what was exposed, how companies responded, and what it means for businesses and consumers.