Intermarché recently experienced a data breach, continuing a trend seen last year with Marks & Spencer, Co-op, and Harrods in the UK. Matthieu Trivier from Semperis delves into why the retail sector is often targeted by cyberattacks and discusses proactive measures retailers can adopt.
Scientists confirm: This is the most effective way to get your cat’s attention, according to new research
Elderly Couple Refuses Reserved Seats—Viral Train Standoff Sparks Fiery Debate on Courtesy
- After last year’s incidents involving Marks & Spencer, Co-op, and Harrods in the UK, why is the retail industry in France, as seen with Intermarché, particularly vulnerable?
- Why are customer identity data as valuable to attackers as payment systems? What can hackers achieve with a name, birth date, or loyalty card number?
- What new phishing scenarios should consumers be wary of with this type of data? Are we witnessing a new era of highly targeted phishing?
- According to French Breaches, a cybercriminal claims to have more data than the 287,605 customer accounts acknowledged by Intermarché. What does this discrepancy indicate about the challenges of accurately assessing the scope of a breach when it is first revealed?
- You work for Semperis, specializing in corporate identity cybersecurity. How does this relate to an incident like Intermarché’s, where a customer database was targeted?
- Given the increasing frequency of these incidents, what should a retailer’s first step be to limit damage in the event of a breach?
- Do you think the retail sector is behind on these issues compared to other industries you work with, such as finance or manufacturing, or are incidents just more visible to the public?
Why You Should Never Reheat These Foods in the Microwave – The Hidden Dangers Experts Warn About
I tried the top 5 guard dogs—here’s what makes these breeds the ultimate protectors
Intermarché’s Drive service recently saw the exposure of personal information belonging to 287,605 customers. To understand why this sector is particularly vulnerable, and what an attacker can actually do with a name, birthdate, or loyalty card number, we spoke to Matthieu Trivier, Associate VP of Pre-Sales at Semperis. He shared insights on the proactive steps a retailer can take to mitigate damage rather than discovering their defensive posture post-incident.
Matthieu Trivier, Associate VP of Pre-Sales, Semperis
Matthieu Trivier, with over 20 years of experience in identity technologies and cyber resilience, assists organizations in securing their Active Directory and hybrid environments. He frequently addresses issues related to protection, detection, and recovery from attacks targeting digital identities.
Why is the retail industry particularly vulnerable?
The retail sector checks several boxes. First, there’s volume: loyalty programs, order histories, online accounts—all represent massive customer databases. Then, the attack surface has expanded rapidly with the rise of e-commerce, click & collect, and mobile apps, outpacing IT and security teams, unlike in banking or insurance where regulations have long enforced a baseline maturity. Lastly, there’s a constant pressure on availability: a downed Drive service immediately translates to lost revenue, so security often takes a backseat to service continuity in budget decisions.

The likes of Marks & Spencer, Co-op, Harrods last year, and Intermarché now show that this isn’t a coincidence but a sector that has grown digitally faster than defensively.
How valuable are customer identity data to attackers?
While a name, birthdate, or loyalty number alone won’t directly drain a bank account, they are key identity elements. These details often serve as verification elements at many service providers, banks, or government bodies to confirm identity. A loyalty number, combined with order history, allows an attacker to credibly impersonate a retailer’s customer service.
Once exposed, these details can’t be canceled like a bank card; they remain exploitable for months, even years after the breach. When combined with other data, they can create increasingly accurate profiles of individuals.
What new phishing scenarios should consumers watch for?
The most likely scenario is receiving a seemingly genuine SMS or email impersonating Intermarché, complete with correct names, orders, and loyalty numbers, perhaps claiming a delivery issue or expiring loyalty points. The link leads to a fake site designed to harvest banking details the initial leak didn’t capture. There could also be phone calls (vishing) where the caller appears highly knowledgeable about the customer’s account.

The significant change here is that classic advice against poorly written or generic messages no longer applies; these messages are personalized with accurate data, often crafted with the help of AI, thus lacking the errors that once signaled phishing.
This is the new era of highly targeted phishing: it’s no longer as random as before and is now based on verifiable facts.
What does the discrepancy in reported data breach figures indicate about the challenges of breach assessment?
This discrepancy is typical in such incidents. At the time of disclosure, a company reports a figure it can substantiate, i.e., accounts where internal investigations have confirmed access or exfiltration. The attacker, on the other hand, faces no obligation to be precise and might include duplicates, outdated data, or inflate numbers to enhance credibility and pressure on the victim.
In both scenarios, the true scope can only be determined through a comprehensive forensic analysis of the identity infrastructure and access logs—a process that can take weeks!
The takeaway here is that the figure announced on day one is almost always a low estimate and not necessarily the final count.
How does your expertise at Semperis relate to an incident like this?
Semperis specializes in the security of enterprise identity systems, like Active Directory and Entra ID, used by over 90% of organizations globally. In an incident like Intermarché’s, where a customer database was targeted, the critical question is how the attacker accessed this database. Typically, the database itself isn’t hacked directly. Instead, it’s often a privileged account or service account within the identity system that’s compromised, allowing the attacker lateral movement to internal applications and databases.
This is precisely what we protect: the layer that decides who or what can access what, often the least monitored link in the chain.
What should retailers do first to limit damage in a breach?
The first step is to shift from wondering “if” to “when” an attack will occur and plan accordingly. This is known as an “assumed breach” posture.
Practically, this means identifying in advance which systems and databases would cause the most damage if compromised and monitoring them continuously rather than discovering them post-incident.
This also means having a written, tested incident response plan ready, so there’s no need to improvise under pressure on the day. Having isolated backups from the production system so you can restart quickly without depending on a ransom is crucial.
And it involves promptly and clearly informing customers, as Intermarché did by notifying CNIL and alerting its customers upon detection, because an informed and vigilant customer can themselves limit the impact of subsequent phishing campaigns.
Is the retail sector lagging behind in security compared to other industries?
Honestly, it’s a bit of both. Finance and to a lesser extent, manufacturing, are ahead because regulations have forced them to be, with appropriate budgets and teams to match the risk. Retail has seen a rapid digital transformation with e-commerce, drive services, apps, and loyalty programs without always keeping pace with security measures.
So yes, there’s significant catching up to do, particularly regarding identity security, the most common entry point for attacks. But these incidents also tend to be more visible because a breach at a retailer directly affects millions of individuals, who receive emails, discuss them, whereas a breach in a bank’s or manufacturer’s internal systems often remains confined to a professional audience.
Both are true: there’s a real security task at hand, and it’s more visible here because it directly impacts the general public.
Similar Posts
- Data Breach Alert: Step-by-Step Guide on How to Respond Effectively
- Data Breaches Soar: France Ranked Second Most Targeted Nation, Just Behind the US
- Received a Strange Email from Instagram? Don’t Worry, Your Account is Safe!
- Hackers Shift Headquarters: Is Your Favorite Collaboration Platform Their New Den?
- AI and Ethics: Can We Truly Trust Artificial Intelligence?

Jordan Park writes in-depth reviews and editorial opinion pieces for Touch Reviews. With a background in UI/UX design, Jordan offers a unique perspective on device usability and user experience across smartphones, tablets, and mobile software.