Technology News

LDLC hacked for the fourth time: customer data leaked

LDLC hacked for the fourth time customer data leaked.jpg

LDLC, a computer equipment marketer, confirms a new hack with leakage of customer data after unauthorized access by a malicious actor to one of its information systems. Customers’ personal information will be able to be consulted, while bank details, identifiers and passwords will not be affected.

LDLC logo

Leaked customer data (again)

The LDLC group has begun notifying affected customers by email. The message indicates that a “a malicious act allowed unauthorized access to one of our information systems”with a query of certain data. The company does not specify the date of the intrusion, the method used or the number of people affected.

The accessible information forms a set sufficiently detailed to facilitate the identification of a client. They include in particular:

  • name
  • first name
  • Mailing address
  • email address
  • cell phone number
  • landline phone number
  • fax number (if provided)
  • customer language
  • civility
  • customer technical codes
  • type of client (individual or professional)
  • date of last connection to web client account
  • date of registration on the site

LDLC claims, however, that banking details, particularly RIB and bank card numbers, remained out of our reach. According to the company, login IDs and passwords were also not exposed. The group indicates that it isolated the system in question, reviewed its access strategy and reported the incident to the CNIL.

The fourth LDLC hack since 2021

This new case constitutes the fourth hack of LDLC since 2021. In December 2021, the group announced unauthorized access to its data following an attack claimed by the Ragnar Locker group. In 2024, LDLC suffered two new leaks: the first, announced at the end of February, concerned the data of 1.5 million customers, while a second leak was revealed in December without the company communicating the number of people affected.

The new incident above all presents the risk of spear phishing. With a customer’s name, address, phone number, and specific account information, a scammer can create a much more credible fake email, text message, or call posing as LDLC, a carrier, or a service department. Therefore, LDLC recommends not clicking on links received by message and never transmitting passwords or banking details by email, SMS or telephone.

At the moment the scope of the leak is unknown: LDLC has not communicated either the number of clients affected or the volume of data potentially consulted. The company simply states that it has taken measures to isolate the affected solution and has notified the CNIL.

Shares:

Related Posts