French retailer Auchan is informing that some sensitive data associated with loyalty accounts of several hundred thousand of its customers was exposed in a cyberattack.

The company is sending data breach notifications to customers affected by the incident.

"We are writing to inform you that Auchan has been the victim of a cyberattack. This attack resulted in unauthorized access to certain personal data associated with your loyalty account," reads the retailer's notification.

According to the sample of the notice, the data exposed in the attack includes full names, title and client status, postal address, email address, phone number, and loyalty card number.

The retailer underlines that bank data, passwords, and PIN numbers have not been impacted.

Notice Auchan sent to customers
Source: Zataz

In a statement for French media, a company representative said that data belonging to "several hundred thousand" of its customers was exposed containing the incident.

Auchan is a French multinational retail group operating over 2,100 branches across 13 countries in Europe and Africa. The chain employs 154,000 people and has an annual revenue of over $35 billion.

The company said it has notified the French Data Protection Authority (CNIL) about the data breach.

In the meantime, Auchan advises letter recipients to remain vigilant for potential phishing attacks leveraging the stolen information.

"We remind you that Auchan will never ask you (whether by email, SMS, or phone) for your login details, passwords, or loyalty card PIN code," warned Auchan.

"If you receive such a message, do not click on any link, do not call the indicated number, and ignore the information it contains, as it is most likely a phishing attempt."

BleepingComputer contacted Auchan several days ago to request more information about the attack, but the company has not provided a reply.

The data breach at Auchan comes shortly after similar disclosures made by other large entities in France, including Air France and KLM, Orange, and Bouygues Telecom, some of which were linked to ShinyHunters' attacks on Salesforce.

At this time, there's no evidence linking these attacks or suggesting a coordinated campaign targeting large businesses in the country.

Break down IAM silos like Bitpanda, KnowBe4, and PathAI

Broken IAM isn't just an IT problem - the impact ripples across your whole business.

This practical guide covers why traditional IAM practices fail to keep up with modern demands, examples of what "good" IAM looks like, and a simple checklist for building a scalable strategy.

Related Articles:

French DIY retail giant Leroy Merlin discloses a data breach

Retail giant Coupang data breach impacts 33.7 million customers

Coupang to split $1.17 billion among 33.7 million data breach victims

Askul confirms theft of 740k customer records in ransomware attack

700Credit data breach impacts 5.8 million vehicle dealership customers