We use cookies on this website.

By clicking "Accept," you agree to the storage of cookies on your device to improve your browsing experience, analyze site usage, and contribute to our marketing efforts. See our privacy policy for more information.

Intermarché Drive: The Security Breach Explained, and What an SME Needs to Check

Les Mousquetaires confirms a cyberattack that exposed approximately 300,000 Intermarché Drive customers. No banking data was compromised, but there was a credible phishing attempt. SME best practices.

Intermarché Drive: The Security Breach Explained, and What an SME Needs to Check

In summary. Intermarché’s Drive service suffered a data breach affecting 287,605 customers, including names, contact information, and order details, but no passwords or banking information. The real risk for an SME is not direct: it lies in the highly targeted phishing campaigns that this data makes seem credible.

What Happened

On August 3, 2026, the Les Mousquetaires group, the parent company of Intermarché, confirmed a cyberattack that occurred in late July targeting customer files on its Drive service, the online ordering and in-store pickup platform. The retailer estimates that 287,605 customers were affected, out of a total of approximately two million accounts.

The exposed data includes first and last names, phone numbers, mailing addresses, dates of birth, loyalty card numbers, and certain order details such as order numbers and amounts. Intermarché notes, however, that passwords, email addresses, banking information, and loyalty points balances were not compromised. The retailer has notified affected customers via email and warned of an increased risk of phishing attempts. These details were reported by Usine Digitale, Le Monde Informatique, and Génération-NT.

Does this apply to me?

An SME may not be a customer of Intermarché Drive, but its employees often are in their personal capacity. That’s where the risk lies. With a real name, phone number, address, and order history, a scammer can craft a very convincing text message or phone call—pretending to be customer service, asking for package confirmation, or citing a payment dispute. An employee who has been trusted with personal information is also more likely to let their guard down at work.

The risk is rising for executives and accounting departments. Accurate personal data is used to lend credibility to identity theft, set up wire transfer fraud, or initiate contact ahead of an urgent request. If your company reuses the same numbers or addresses for business accounts, the risk extends to your business operations.

What to Do Now

Three reflexes, from the most immediate to the most fundamental.

1. Notify your teams today. A short message will suffice: a phishing campaign claiming to be from Intermarché is likely; do not click on any links received via text message or email; use the app or the official website to verify anything.

2. Be extra vigilant with sensitive requests. Any change to bank account information, any unusual transfer, or any urgent request should be verified through a second known channel (such as a call back to a trusted number). Remind the finance and procurement departments of this rule.

3. Review your own customer databases. If you handle personal data, assess your encryption, access segregation, multi-factor authentication, and logging practices. These are also the minimum requirements set forth by the NIS2 Directive for affected companies.

‍

Not sure about your exposure?

Get an update from an IT Systems expert

A quick assessment of your exposure and the steps you should take. No obligation.

Request an exchange

‍

In a nutshell

The Intermarché data breach isn’t targeting your company, but it fuels more targeted scams aimed at your employees and executives. A reminder to stay vigilant and a clear policy on sensitive requests cover most of the risk. With the right procedures in place, this type of incident remains manageable.

Frequently asked questions

Have our business data been leaked? No, the leak involves personal accounts on Drive Intermarché. The risk to the company is indirect, through phishing attacks targeting your employees.

Should we change our passwords? According to the company, no passwords have been compromised. Nevertheless, be on the lookout for messages asking you to enter a password via a link you’ve received.

— Samir Amara, CEO — IT Systèmes

Our latest articles

See more

ASP: The Data Breach Explained, and What an SME Should Check Immediately Afterward

The Services and Payment Agency (ASP) has confirmed a data breach affecting more than 143,000 recipients of the “Coup de pouce énergie” assistance program, with IBANs and Social Security numbers exposed. For an SME, this incident highlights a risk that is easy to check internally: a vulnerability in document access that a public or private website may have without realizing it.
September 25, 2026
AI and Cybersecurity Illustration
Cybersecurity

AI and Cybersecurity: The 3 Key Challenges for SMEs and Mid-Sized Companies

AI and Cybersecurity: Securing Your Use of AI, Using It to Defend Yourself, and Countering AI-Powered Attacks. A Guide for Small and Medium-Sized Businesses.
September 25, 2026
Illustration of an agent-based infrastructure operator
Cybersecurity

Agent-Based Infrastructure Operator: Definition and Role

An agent-based infrastructure operator designs, secures, and continuously operates the layer that enables AI agents to act within the information system. Definition, components, a Microsoft 365 example, and eight questions to help you choose an operator.
September 24, 2026
Illustration: iA Agent
Cybersecurity

Agent-Based AI: Definition, How It Works, and Applications

Agent-based AI refers to AI systems capable of pursuing a goal autonomously: they gather information, plan steps, take action within software, and adjust their plan based on the outcome. Definition, operation, risks, governance, and business applications.
September 24, 2026
Abstract illustration of cybersecurity
Cybersecurity

Brevo: The Data Breach Explained, and What an SME Should Check Immediately Afterward

Brevo, the French email marketing platform used by tens of thousands of small and medium-sized businesses, suffered two security incidents in early September 2026: a breach via an authentication vulnerability, followed by the theft of a technical key that allowed malicious code to be injected into client websites. This week, Trezor and Paymium confirmed the extent of the impact on their users. Here’s what an SME that uses Brevo—or one of its widgets—needs to check.
September 24, 2026
Illustration: Protecting Your Small Business from Cyber Threats
Cybersecurity

How to Protect Your Small Business from Cyberattacks in 2026

Technical prevention, business continuity planning (BCP)/disaster recovery planning (DRP), and cyber insurance: the three lines of defense to protect your small business from cyberattacks in 2026.
September 24, 2026