French supermarket chain Intermarché has confirmed a cyberattack that gave unauthorised access to personal data belonging to customers of its Drive click-and-collect service. Groupement Les Mousquetaires, which operates the brand, says 287,605 customers were identified as affected, out of roughly two million users of the service. The incident, which occurred last week, has been notified to France's data protection authority, the CNIL, and to the Paris public prosecutor.
The query "cyberattaque Intermarché" entered French search trends on the morning of 4 August, with more than 20,000 searches over the day.
Key points
- 287,605 Drive customers affected, out of roughly two million users of the service.
- Data exposed: first and last name, postal address, phone number, date of birth, loyalty card number, and some information tied to Drive orders.
- No banking data appears to be involved.
- Notified to the CNIL and the Paris prosecutor.
- Affected customers are urged to be especially wary of scam attempts.
Why the absence of banking data does not make this harmless
That is the detail that reassures people wrongly. A dataset combining name, postal address, phone, date of birth and order history does not open a bank account — but it makes the attack that does, targeted phishing, convincing at almost no cost.
The difference is concrete. A generic message about a delivery problem is easy to spot. A message quoting your name, your exact address, the date of your last Drive order and digits from your loyalty card is not — it looks like what the retailer would actually send. That is precisely what this kind of leak enables, which is why the advice to stay vigilant is not boilerplate.
The practical rule is simple: never follow a link that arrives by text or email about an order. Go to the retailer's own site or app and check there.
The real story for businesses: the clock starts at awareness
For organisations reading this and wondering "what if it were us", the heart of the matter is the regulatory timetable.
GDPR article 33 requires notifying the supervisory authority within 72 hours, and that window runs from the moment the organisation becomes aware of the breach — not from the intrusion. A March intrusion discovered in August starts its 72 hours in August. Article 34 adds that where the risk to individuals is high, they must be told as well, without undue delay. Here, the combination of identity, contact details and order history is exactly the profile that pushes toward telling people.
Two points are worth knowing because they run against intuition:
- Late notification is provided for. A notification beyond 72 hours must carry the reasons for the delay. The worst outcome is not being late; it is not notifying at all and having the authority find out another way, which turns an incident that happened to you into a failure attributed to you.
- The GDPR does not stop at the EU border. A Tunisian or Saudi company holding data on European residents falls within its scope regardless of where it is incorporated. "We are not in Europe" is not an exemption — and it is the most common mistake among North African and Gulf companies serving European customers.
This matters all the more because the regimes genuinely diverge. Saudi Arabia's PDPL also imposes 72 hours to notify SDAIA, but with no materiality threshold: a company cannot decide a breach was too small to report. Conversely, Tunisia's organic law 2004-63, which predates the GDPR, sets no breach-notification obligation on a fixed deadline at all.
We have published a breach notification deadline calculator that takes the moment of awareness and the jurisdictions involved and works out the deadline for each authority. It runs in the browser: no incident detail is transmitted.
For the technical side — detecting a leak, dating awareness defensibly, and producing what a notification has to contain — the breach notification readiness guide covers the implementation.
What to take away
A leak without banking data is still an exploitable leak, and compliance is not decided on the day of the incident but before it: knowing what data you hold, where it lives, and being able to date precisely the moment you knew. The organisations that spend the first day of a crisis answering those questions are the ones that burn their 72 hours on an internal investigation.