In summary. The Allo E.Leclerc customer service team notified certain customers that one of its logistics providers had been hacked: names, email addresses, and phone numbers were compromised, though no banking information was stolen. For a small or medium-sized business, the lesson here is not the brand that was affected, but the route taken: it only takes one supplier to expose the data you entrust to them.
What Happened
On August 26, 2026, customers of the Allo E.Leclerc service received a notification from LCommerce, the company that operates the service. An external logistics provider was breached, and the attackers were able to access customer data held by that partner. The news was reported on August 27 by Cyberattaque.org, French Breaches, and Génération NT.
Three categories of data have been confirmed: first and last name, email address, and phone number. LCommerce specifies that bank account information, login credentials, and passwords are not affected. The company has notified the CNIL and directly informed the individuals concerned.
Several details remain unknown at this point: the name of the service provider, the exact date of the breach, the number of affected customers, and the volume of data compromised. We will therefore stick to what has been confirmed.
Does this apply to me?
Two options, depending on your situation.
If your employees are customers of the service, the risk is phishing. A name linked to an email address and a phone number makes it possible to send a credible text message or email on behalf of a retailer or shipping company. This is the typical scenario in the weeks following this type of data breach.
If you run a small or medium-sized business, the issue is different. You likely entrust data to third parties: a logistics provider, a payroll firm, a SaaS vendor, a call center, or a marketing agency. Each of them holds a copy of your customer or employee files. A breach at any one of them puts you at risk, even if your own IT system remains secure. Many companies only realize at the time of an incident that they don’t know exactly who holds what data.
Here’s a simple test: if you can’t answer the question “Which service providers currently hold personal data about our customers or employees?” within ten minutes, the issue warrants a morning’s worth of work.
What to Do Now
1. Compile a list of your service providers that hold data. Include the provider’s name, the type of data, the approximate volume, and the person responsible internally. The GDPR already requires this record of data processors, but it is often incomplete or out of date. Start by reviewing this year’s supplier invoices to ensure you don’t miss anything.
2. Review what your contracts stipulate in the event of an incident. The key point is the notification timeframe: within how many hours does your service provider commit to notifying you, and who do you actually call? Make a note of a specific contact person and a phone number—not a generic support address. Without this information, you’ll lose those first few hours—the ones that matter most.
3. Prepare your teams for bounce-back phishing. After a data breach at a third-party provider, phishing attempts often use real information, which makes them seem credible. One rule covers the essentials: any change to bank information, shipping address, or password must be verified through another channel, such as by calling a known number. Write down the rule, share it, and make it clear that reporting a suspicion will never be held against anyone.
If you are subject to the NIS2 Directive, these three points directly address the supply chain security requirements. You might as well address them once for both purposes.
Not sure about your exposure?
Get an update from an IT Systems expert
A quick assessment of your exposure and the steps you should take. No obligation.
In a nutshell
A well-established company may find that customer data leaks through a service provider, even if no security vulnerability within the company itself has been exploited. The data involved here is limited, but it fuels highly targeted phishing campaigns. For an SME, the solution lies in maintaining an up-to-date list of its subcontractors, having written notification deadlines clearly stipulated, and implementing a verification policy that everyone is familiar with.
None of this requires a specific budget. It involves a morning of thorough review, followed by an annual review. Our teams can help you structure this process if you’d prefer not to handle it on your own.
Frequently asked questions
My service provider has been hacked: Do I need to report this to the CNIL? If the data in question belongs to your customers or employees, you remain the data controller and are responsible for reporting the incident within 72 hours of becoming aware of it, unless the risk to individuals is negligible.
How can you tell if an email you receive after a data breach is fraudulent? Don't trust the content—it may be accurate. Always verify through an independent channel: call a number you already know, or log in through your usual customer portal instead of clicking the link in the email.
Should you change your passwords? In this specific case, passwords are not affected. However, if you use the same password across multiple services, you should change it anyway: it’s password reuse that turns a minor leak into a serious incident.
— Samir Amara, CEO — IT Systèmes


.jpeg)


.jpeg)
