Security · October 5, 2026
Also published in العربية
LDLC Notify Customers of Third Data Breach Since 2024
LDLC, a French computer hardware retailer, sent an email to customers on Friday 2 October 2026 informing them of an unauthorized access to one of its information systems. The breach may have exposed personal data including names, addresses, email addresses, phone numbers, fax numbers, civil titles, languages, client types, internal client codes, registration dates, and last login dates. LDLC confirmed that no payment cards or passwords were compromised. Cybersecurity consultant Christophe Boutry was among the first to amplify the alert on X. The email did not disclose the number of affected customers, the method of intrusion, or the exact date of the breach.
LDLC stated it had isolated the affected tool, reviewed system accesses, and reported the incident to the CNIL, France’s data protection authority. The company warned that attackers could craft convincing phishing messages using details such as civil titles, registration dates, and last connection dates to impersonate LDLC representatives. LDLC emphasized that its staff never request passwords, banking details, or RIB changes via email, SMS, or phone calls. The breach marks the third data incident involving LDLC since 2024, following a February 2024 leak attributed to the Epsilon Group affecting only physical store customers, a December 2024 incident with limited details, and a 2021 breach by Ragnar Locker that involved the sale of approximately 29.5 GB of internal data.
Recent similar incidents include Carrefour notifying some clients about a breach at one of its service providers that exposed names, emails, and phone numbers. Affected customers are advised to contact LDLC’s data protection officer via the site’s contact page or file a complaint with the CNIL if their rights are violated. The company also shared guidance videos on responding to data leaks. LDLC added a promotional WhatsApp channel for deals, which it described as spam-free.