On Friday, October 2, LDLC, a computer equipment reseller based in Lyon, France, informed its customers that a malicious third party had gained unauthorized access to one of its information systems. This breach potentially exposed personal data, including names, postal addresses, email addresses, landline and mobile phone numbers, and in some cases, fax numbers. Additional account-related information, such as titles (like Mr., Mrs., or Doctor), language preferences, customer type (individual or professional), internal customer codes, registration dates, and last login dates, may also have been accessed. However, LDLC confirmed that passwords, login identifiers, credit card numbers, and RIBs (bank account details) were not compromised.
The company stated that it isolated the affected system immediately after detecting the breach and reported the incident to the CNIL, France’s data protection authority, as required by law. However, the email sent to customers did not provide specific details such as the number of people affected, the date of the breach, the method used, or the identity of the attacker.
This incident is the third data breach involving LDLC since 2024. In late February 2024, the Epsilon Group claimed to have stolen approximately 1.5 million customer records, which LDLC confirmed affected only customers of its physical stores. In December 2024, the company announced another cybersecurity incident, though details were limited. Earlier, in late 2021, LDLC was targeted by the Ragnar Locker ransomware group, which encrypted company files and demanded a ransom. The group later sold nearly 29.5 GB of internal data.
Other recent cybersecurity incidents include Carrefour informing customers of a breach involving names, emails, and phone numbers due to an issue with a service provider. Similarly, the billing software VosFactures confirmed a breach after the hacking of its Polish service provider. France’s national cybersecurity agency, ANSSI, reported a breach of the tax office website, and the Agency for Payment Services (ASP) experienced a breach where IBANs of 143,000 beneficiaries of the Energy Boost program were stolen. In the United States, the personal records of 3 million military personnel were stolen from a Pentagon agency.
LDLC has advised customers to be cautious of phishing attempts and to verify the authenticity of any communication claiming to be from the company. Affected customers can contact the company’s data protection delegate through its website. If customers believe their rights are not respected, they may file a complaint with the CNIL.
LDLC Customers Notified of Data Breach Involving Personal Information
AI-rewritten from original reportingHow it works
data-breachcybersecurityldlcfraud-preventioncustomer-datafraud



