Carrefour has warned French customers about a data breach at a third-party supplier. Attackers may have gained access to names, email addresses, and phone numbers through the delivery platform Shipup. Other French retailers also appear to have been affected.
Domino effect in French retail
Early September, Carrefour informed a number of customers in France about a security incident involving an external service provider. First and last names, email addresses, and phone numbers may have been compromised. According to Carrefour, no passwords or banking information were leaked.
The supermarket group did not name the supplier involved. However, the French specialized website Cyberattaque.org links the incident to Shipup, a platform that online stores use for package tracking and communication following an online purchase. Retailers such as Aroma-Zone and the department store chain Printemps also use the platform and were recently affected. Shipup works with more than 700 brands.
At Carrefour, there are no indications that its own online store, customer accounts, or internal systems were hacked. The breach involves personal data that the retailer had provided to its service provider for delivery-related communications. Carrefour advises its French customers to be extra vigilant regarding suspicious emails and text messages. The retailer has not disclosed exactly how many customers were affected.
Is your system truly secure? As a retailer, how can you protect yourself against cyberattacks? In a spectacular show at RetailDetail Night, famous ethical cyber hacker Inti De Ceukelaire will reveal the reality of the situation.
Don’t miss this impressive eye-opener—order your tickets now for the AI in Retail pre-show.
Europe - EN
België - NL
Nederland - NL
España - ES
France - FR


