GDPR Compliance Software for French SMEs: The Complete Guide
Discover how to choose the best GDPR compliance software for French SMEs. Compare features, pricing, implementation, and CNIL compliance requirements.
Another week, another major French retailer added to the growing list of cyberattack victims. On August 3, 2026, the Groupement Mousquetaires, the parent company behind Intermarché, confirmed that its online grocery service, Drive Intermarché, had suffered a cyberattack that exposed...
Another week, another major French retailer added to the growing list of cyberattack victims. On August 3, 2026, the Groupement Mousquetaires, the parent company behind Intermarché, confirmed that its online grocery service, Drive Intermarché, had suffered a cyberattack that exposed the personal data of nearly 300,000 customers.
The incident is a reminder that even long-established retail brands with millions of loyal shoppers are not immune to cyber threats. For anyone who has ever placed a click-and-collect order through Intermarché's Drive service, or who simply follows how European retailers are handling data protection, this breach is worth understanding in detail.
According to Intermarché, the cyberattack took place during the last week of July 2026 and targeted the customer files linked to its Drive service, the platform customers use for online grocery orders and click-and-collect purchases. The breach was first reported by the cybersecurity outlet French Breaches before Intermarché confirmed the incident to French media.
The company described the event as unauthorized access to certain confidential customer data. As of the disclosure, 287,605 Drive customers, out of a Drive customer base of roughly two million, had been identified as affected and notified directly. Intermarché also said additional investigation was underway to determine whether more accounts had been compromised, so the final number could still grow.
Data breach severity usually comes down to one question: what exactly did the attackers get their hands on? Intermarché has been fairly transparent about the scope of the exposure, and the picture is mixed. Sensitive personal identifiers were compromised, but the company says financial data was not touched.
| Data That Was Exposed | Data That Was Not Accessed |
| Full names | Banking details |
| Phone numbers | Loyalty point balances |
| Postal addresses | Account passwords |
| Dates of birth | Email addresses |
| Loyalty card numbers | |
| Partial online order history |
On paper, this looks like it could have been worse. No payment cards, no bank account numbers, no passwords. But security professionals tend to push back on the idea that a breach without financial data is a "minor" breach. Names, phone numbers, birthdates, and order history are exactly the raw materials attackers need to build convincing phishing and impersonation campaigns. That combination of details is often more dangerous in the wrong hands than a stolen card number, because a card can be cancelled in minutes while a person's identity profile cannot.
To its credit, Intermarché moved relatively quickly once the incident was confirmed. The group notified the CNIL, France's national data protection authority, in line with its obligations under the GDPR's 72-hour breach notification rule. It also filed a formal complaint with the Paris public prosecutor's office, opening the door to a criminal investigation alongside the regulatory review.
Affected customers were contacted directly by email or letter and advised to stay alert for phishing attempts. Intermarché specifically warned that the stolen data could be used to make scam calls, texts, or emails appear more credible, since a message that references your real name, address, and recent order history is far more convincing than a generic scam attempt.
This is a fairly standard playbook for post-breach communication: notify the regulator, notify the customers, and warn people about downstream social engineering risks. Whether it goes far enough, particularly around monitoring for a possible increase in the affected customer count, is something regulators and privacy advocates will likely continue to scrutinize as the investigation develops.
Intermarché is not an isolated case. France's retail and telecom sectors have faced a wave of high-profile breaches over the past couple of years, and each one tends to follow a similar pattern: a large customer database, a third-party service or legacy system as the point of entry, and personal data ending up in the hands of attackers who use it for phishing rather than direct financial theft.
Retailers are attractive targets for a simple reason. They sit on enormous stores of customer data collected through loyalty programs, online ordering platforms, and click-and-collect services, yet many of them were not originally built as data-security-first organizations. E-commerce and loyalty systems were often bolted onto older retail infrastructure over time, which creates exactly the kind of fragmented environment that attackers look for.
For a closer look at how this specific incident unfolded, France Info's coverage of the Intermarché breach includes the group's own statement and further detail on the ongoing investigation.
If you shop through Drive Intermarché, or you have simply received a notification about this breach, a few practical steps go a long way toward reducing your exposure.
| Action | Why It Matters |
| Treat unexpected calls or texts with caution | Scammers may reference your real name, address, or order history to sound legitimate. A business that already has your data will rarely ask you to confirm it over the phone. |
| Never click links in unsolicited messages | Go directly to the official Intermarché website or app instead of clicking a link sent by email, text, or messaging app. |
| Watch for identity-related fraud | Because dates of birth were exposed, keep an eye out for unfamiliar accounts, credit applications, or subscription sign-ups in your name. |
| Update passwords out of caution | Passwords were not confirmed as exposed, but changing your Intermarché password, and any other account where you reuse it, is a low-effort precaution. |
| Report suspicious activity | If you receive a scam attempt referencing this breach, report it to Intermarché and, in France, to the platform Cybermalveillance.gouv.fr. |
Beyond the immediate impact on Intermarché's customers, this incident is a useful case study for any organization that stores customer data, which today is essentially every organization. A few takeaways stand out.
First, breach notification speed matters. Intermarché notified the CNIL and reached out to customers within a short window of discovering the incident, which is exactly what GDPR expects and what limits reputational damage. Organizations that delay disclosure, or try to downplay the scope of an incident, tend to face far harsher scrutiny once the full picture becomes public.
Second, "no financial data was accessed" is not the same as "no harm was done." Names, phone numbers, and order history are enough to power convincing social engineering attacks, and businesses need to communicate that risk clearly to customers rather than framing a breach as low severity just because payment details were untouched.
Third, most breaches like this one trace back to gaps that are entirely preventable with the right combination of employee awareness and a tested incident response plan. Attackers frequently succeed not because of some unbreakable technical exploit, but because of a weak point in process, whether that is a phishing email opened by an employee, a misconfigured system, or a slow response once suspicious activity is first detected.
This is exactly where structured training makes a measurable difference. Teams that understand how phishing and social engineering attacks actually work are far less likely to be the entry point for an attacker. And organizations with a rehearsed incident response plan can contain a breach, notify regulators, and communicate with customers in hours rather than days, which directly limits the damage.
If your organization wants to reduce the human-error risk that sits behind most breaches like this one, our Cyber Security Awareness Training course walks employees through exactly the kind of phishing and social engineering tactics that follow a data breach of this scale. And if you want your team prepared to respond the moment an incident is detected, rather than scrambling to figure out next steps, our Cybersecurity Incident Response Training covers the practical playbook, from containment to regulatory notification, that separates a well-handled breach from a reputational crisis.
Strengthen Your Incident Response
Prepare your team to detect, assess, contain and respond to cybersecurity incidents effectively. Build a structured response process, clarify responsibilities and reduce the operational and regulatory impact of cyberattacks. Earn a recognized PDF certificate — free with the course. Self-paced, role-ready, and built to make you hireable.
Learn More →The Intermarché breach will likely fade from headlines within a week or two, as these stories usually do. But for the 287,605 people already notified, and potentially more once the investigation concludes, the risk of targeted phishing attempts is far from over. And for every business watching from the sidelines, the real takeaway is not about Intermarché specifically. It is about how quickly any organization holding customer data can find itself in the same position, and how much of that risk comes down to preparation rather than luck.
Data breaches are no longer a rare, one-off crisis. They are a recurring risk that every organization needs to plan for, train for, and be ready to respond to. Staying informed about incidents like this one is a good first step. Building the internal awareness and response capability to prevent your organization from becoming the next headline is the step that actually matters.
You can find more on cybersecurity and compliance on our blog.