LDLC notifies its customers of a fourth data breach since 2021
Since 2 October, LDLC has been telling its customers that unauthorised access to one of its systems may have exposed their full contact details. It is the retailer's fourth incident of this kind since 2021, and that data is enough to make a phishing attempt convincing.

What the letter to customers says
Since 2 October 2026, LDLC has been emailing its customers about a new security incident, Next reports. In the message, the retailer writes that “a malicious act allowed unauthorised access to one of our information systems, which may have resulted in certain data concerning you being viewed”.
The wording is careful. It talks about data that may have been viewed. It does not say which system was targeted, when the intrusion happened or how many customers are affected. None of this has been made public so far.
The data exposed
The list LDLC has shared is long. It includes first and last name, postal address, email address, fax number, mobile and landline numbers, the customer’s language, title (Mr, Ms and so on), internal customer codes, customer type (individual or business), the date the account was created on the site and the date of the last login to the online customer account.
According to LDLC, no banking data (bank account details, card numbers) and no login credentials or passwords are affected. The company says it immediately isolated the affected part of its infrastructure, revised the access policy for it and notified the incident to the CNIL, France’s data protection authority.
The risk for the people affected
The absence of banking data does not make this breach harmless. With someone’s identity, full contact details, customer status and account age, it is possible to write messages in the retailer’s name that are hard to tell apart from genuine ones. LDLC acknowledges this itself: the information “could be used for fraud and phishing attempts”.
The advice attached to the email follows the same line. Do not click on links received by text message or email, and do not share your personal information, login details or bank details by email, text message or phone. In practice, a message that mentions your LDLC account, the date you signed up or your status as a business customer does not prove it is genuine: those are exactly the details that were exposed. If in doubt, go to the website yourself rather than following a link you received.
A fourth incident since 2021
Next counts four incidents of this kind at LDLC since 2021. That year, the company announced it had been attacked by the Ragnar Locker group, which put 29.5 GB of internal data up for sale. In 2024, two breaches followed one another: the first on 29 February, with the theft of data belonging to 1.5 million customers, then a second in December, for which the number of people affected is not known.
The information available does not explain why these incidents keep happening. LDLC’s email does not say how the intruders got in or whether this breach is linked to the earlier ones. Nor is there anything, at this stage, to suggest that the four incidents share a common cause. Those questions are now for the CNIL, which has been notified.
For customers, the practical consequence is the same as after the previous three: treat with suspicion any message that seems to know a little too much about you.
Sources (1)
Written with AI assistance from the sources cited above, then reviewed and approved before publication by Sébastien Soulier.


