We use cookies on this website.

By clicking "Accept," you agree to the storage of cookies on your device to improve your browsing experience, analyze site usage, and contribute to our marketing efforts. See our privacy policy for more information.

Cybersecurity

Hello, E.Leclerc: The leak came from a service provider—here’s what an SME should check with its own staff

LCommerce, the company that operates the Allo E.Leclerc service, has informed some of its customers that one of its external logistics providers had been hacked. Names, email addresses, and phone numbers were compromised, but no banking information was exposed. The incident was reported to the CNIL and serves as a reminder that a company can be affected even if its own system has not been compromised.

Hello, E.Leclerc: The leak came from a service provider—here’s what an SME should check with its own staff

In summary. The Allo E.Leclerc customer service team notified certain customers that one of its logistics providers had been hacked: names, email addresses, and phone numbers were compromised, though no banking information was stolen. For a small or medium-sized business, the lesson here is not the brand that was affected, but the route taken: it only takes one supplier to expose the data you entrust to them.

What Happened

On August 26, 2026, customers of the Allo E.Leclerc service received a notification from LCommerce, the company that operates the service. An external logistics provider was breached, and the attackers were able to access customer data held by that partner. The news was reported on August 27 by Cyberattaque.org, French Breaches, and Génération NT.

Three categories of data have been confirmed: first and last name, email address, and phone number. LCommerce specifies that bank account information, login credentials, and passwords are not affected. The company has notified the CNIL and directly informed the individuals concerned.

Several details remain unknown at this point: the name of the service provider, the exact date of the breach, the number of affected customers, and the volume of data compromised. We will therefore stick to what has been confirmed.

Does this apply to me?

Two options, depending on your situation.

If your employees are customers of the service, the risk is phishing. A name linked to an email address and a phone number makes it possible to send a credible text message or email on behalf of a retailer or shipping company. This is the typical scenario in the weeks following this type of data breach.

If you run a small or medium-sized business, the issue is different. You likely entrust data to third parties: a logistics provider, a payroll firm, a SaaS vendor, a call center, or a marketing agency. Each of them holds a copy of your customer or employee files. A breach at any one of them puts you at risk, even if your own IT system remains secure. Many companies only realize at the time of an incident that they don’t know exactly who holds what data.

Here’s a simple test: if you can’t answer the question “Which service providers currently hold personal data about our customers or employees?” within ten minutes, the issue warrants a morning’s worth of work.

What to Do Now

1. Compile a list of your service providers that hold data. Include the provider’s name, the type of data, the approximate volume, and the person responsible internally. The GDPR already requires this record of data processors, but it is often incomplete or out of date. Start by reviewing this year’s supplier invoices to ensure you don’t miss anything.

2. Review what your contracts stipulate in the event of an incident. The key point is the notification timeframe: within how many hours does your service provider commit to notifying you, and who do you actually call? Make a note of a specific contact person and a phone number—not a generic support address. Without this information, you’ll lose those first few hours—the ones that matter most.

3. Prepare your teams for bounce-back phishing. After a data breach at a third-party provider, phishing attempts often use real information, which makes them seem credible. One rule covers the essentials: any change to bank information, shipping address, or password must be verified through another channel, such as by calling a known number. Write down the rule, share it, and make it clear that reporting a suspicion will never be held against anyone.

If you are subject to the NIS2 Directive, these three points directly address the supply chain security requirements. You might as well address them once for both purposes.

Not sure about your exposure?

Get an update from an IT Systems expert

A quick assessment of your exposure and the steps you should take. No obligation.

Request an exchange

In a nutshell

A well-established company may find that customer data leaks through a service provider, even if no security vulnerability within the company itself has been exploited. The data involved here is limited, but it fuels highly targeted phishing campaigns. For an SME, the solution lies in maintaining an up-to-date list of its subcontractors, having written notification deadlines clearly stipulated, and implementing a verification policy that everyone is familiar with.

None of this requires a specific budget. It involves a morning of thorough review, followed by an annual review. Our teams can help you structure this process if you’d prefer not to handle it on your own.

Frequently asked questions

My service provider has been hacked: Do I need to report this to the CNIL? If the data in question belongs to your customers or employees, you remain the data controller and are responsible for reporting the incident within 72 hours of becoming aware of it, unless the risk to individuals is negligible.

How can you tell if an email you receive after a data breach is fraudulent? Don't trust the content—it may be accurate. Always verify through an independent channel: call a number you already know, or log in through your usual customer portal instead of clicking the link in the email.

Should you change your passwords? In this specific case, passwords are not affected. However, if you use the same password across multiple services, you should change it anyway: it’s password reuse that turns a minor leak into a serious incident.

— Samir Amara, CEO — IT Systèmes

Our latest articles

See more
Helpy Barometer: Resolution rate for Level 1 tickets measured on the IT Systèmes internal help desk
MSP & Managed IT Services: Proactive IT Management for Small and Medium-Sized Businesses

Helpy 2026 Barometer: 44% of Level 1 tickets resolved without human intervention

44% of Level 1 tickets resolved without human intervention, 3-minute average resolution time, €0.26 per ticket. Eleven months of data collected from our own help desk, including methodology and limitations.
August 28, 2026
IT Security Governance and Steering Meeting in an Open-Plan Office
Cybersecurity

Cybersecurity GRC: Governance, Risk, and Compliance—A Guide for Small and Medium-Sized Businesses

GRC (Governance, Risk, and Compliance) provides a framework for managing IT security. Definition, clarification of differences from CRM, pillars, relationship with NIS2, and implementation for small and medium-sized businesses and mid-sized companies.
August 27, 2026
Cybersecurity

Metabase Vulnerability (CVE-2026-72898): Should SMEs Apply the Patch Immediately?

On August 24, 2026, CERT-FR issued an advisory regarding several vulnerabilities in Metabase, a widely used dashboard tool among small and medium-sized businesses. A few days earlier, the French service provider TeleCoop confirmed that its own instance had been compromised. How to decide whether your company should apply the patch today or next week.
August 27, 2026
Abstract illustration of a data flow related to an artificial intelligence platform
Cybersecurity

Claimed Data Breach at Klark.ai: The Real Risk for Small and Medium-Sized Businesses Using AI Tools

A hacker has claimed responsibility for stealing more than 140 GB of data from Klark.ai, a French AI platform dedicated to customer service. Approximately 500,000 people are reportedly affected, with support conversations, API keys, and a few IBANs among the stolen data. Here’s how to tell if your small business is indirectly at risk—and the three checks you should perform this week.
August 27, 2026

Confidential Computing in 2026: Protecting Your Data Even in Memory, on a Third-Party Cloud

‍Confidential computing encrypts data while it is being processed in memory, not just at rest or in transit. This guide explains what the technology actually protects, what it does not protect according to ANSSI, and how a CIO at an SME or mid-sized company should take this into account when making cloud decisions.
August 26, 2026
Cybersecurity

Tax Agency Hack: What Leaked From the Corporate Side, and the 3 Checks to Perform This Week

The DGFiP has confirmed the theft of data belonging to 678,000 users—both individuals and businesses—following a breach of its information system in late June. For businesses, the scope of the data breach is limited (SIREN numbers, addresses), but this information is enough to make a phishing attempt or wire transfer fraud much more credible. Here’s what was actually leaked and the steps you should take this week.
August 17, 2026