Company Details
auchan
59,994
504,249
43
auchan-retail.com
0
AUC_9335289
In-progress


Auchan Retail Company CyberSecurity Posture
auchan-retail.comTo create new-generation retailing that improves people’s lives, Auchan Retail places customers at the centre of its actions and reaffirms the retailer’s role: that of a multi-format, “phygital” activist for good, healthy, local produce that constantly reinvents itself to deliver a new customer experience – one that’s close, connected, surprising and considerate. Auchan Retail’s 1,985 points of sale offer all forms of retailing in 12 countries: hypermarkets, supermarkets and ultra convenience stores – all supplemented by the power and flexibility of e-retail. We’re one of the largest employer worldwide, with 179,590 employees.
Company Details
auchan
59,994
504,249
43
auchan-retail.com
0
AUC_9335289
In-progress
Between 750 and 799

Auchan Retail Global Score (TPRM)XXXX

Description: French retail giant Auchan suffered a cyberattack in August 2025, resulting in the theft of loyalty account data from several hundred thousand customers. Attackers accessed personal information, including names, postal/email addresses, phone numbers, and loyalty card numbers, though financial data (bank details, PINs, and loyalty balances) remained secure. The breach was detected and contained promptly, with notifications sent to affected customers and France’s data protection authority (CNIL). This marks Auchan’s second major breach in a year, following a similar November 2024 incident targeting loyalty program data. While no passwords or payment credentials were compromised, the stolen data poses risks for targeted phishing attacks or underground sale. Auchan has implemented multi-factor authentication, enhanced network monitoring, and employee cybersecurity training, alongside offering free credit monitoring to impacted customers. Authorities are investigating the attack’s origin, while consumers are warned to stay vigilant against fraudulent communications.


No incidents recorded for Auchan Retail in 2026.
No incidents recorded for Auchan Retail in 2026.
No incidents recorded for Auchan Retail in 2026.
Auchan Retail cyber incidents detection timeline including parent company and subsidiaries

To create new-generation retailing that improves people’s lives, Auchan Retail places customers at the centre of its actions and reaffirms the retailer’s role: that of a multi-format, “phygital” activist for good, healthy, local produce that constantly reinvents itself to deliver a new customer experience – one that’s close, connected, surprising and considerate. Auchan Retail’s 1,985 points of sale offer all forms of retailing in 12 countries: hypermarkets, supermarkets and ultra convenience stores – all supplemented by the power and flexibility of e-retail. We’re one of the largest employer worldwide, with 179,590 employees.

Albertsons Companies is one of the largest food and drug retailers in the United States, with over 2,200 stores in 34 states and the District of Columbia. Our well-known banners include Albertsons, Safeway, Vons, Jewel-Osco, Shaw's, Acme, Tom Thumb, Randalls, United Supermarkets, Pavilions, Star Mar

There’s something different about shopping at SPAR, that’s because we’ve created a culture of caring and community to ensure our customers have a consistently enjoyable shopping experience in a uniquely friendly and family orientated store. Nothing means more to us than our valued customers and we

Costco Wholesale is a multibillion dollar global retailer with warehouse club operations in 14 countries. We are the recognized leader in our field, dedicated to quality in every area of our business and respected for our outstanding business ethics. Despite our large size and rapid international ex

YOU LIVE AND BREATHE SPORTS. SO DO WE. In work and in life. On the field, the court or the ice. Nothing wins like a commitment to excellence; to your team and your goals. At DICK’S Sporting Goods, it’s this kind of thinking that inspires our mission. Our culture is the result of people who give t

About UNIQLO LifeWear Apparel that comes from the Japanese values of simplicity, quality, and longevity. Designed to be of the time and for the time, LifeWear is made with such modern elegance that it becomes the building blocks of each individual’s style. A perfect shirt that is always being made m

Safeway operates as a banner of Albertsons Companies. Locally great and nationally strong, Albertsons Cos. (NYSE: ACI) is one of the largest food and drug retailers in the United States. Albertsons Cos. operates stores across 34 states and the District of Columbia under 20 well-known banners includi

At Nordstrom, we empower our employees to set their sights high and blaze their own trails. This is a place where your success and growth are truly a result of your own efforts and achievements. Our teams are made up of motivated people who work hard to become leaders within the company, at all

Burlington Stores, Inc., headquartered in New Jersey, is a nationally recognized off-price retailer. Burlington is a Fortune 500 company and its common stock is traded on the New York Stock Exchange under the ticker symbol “BURL.” The Company operates more than 1000 stores, in 46 states, Washington

MC is a company from the SONAE group, and is a leader in the food retail industry in Portugal. We are a company made by all, to all. With a history of over 35 years of continuous growth, MC has a distinctive positioning in different business areas, with a vast portfolio of high quality products, se
.png)
Lidl has received approval from France's competition authority to acquire 19 food retail stores operated under the Auchan Supermarché...
The traditional model of large supermarkets is undergoing a profound transformation. Auchan Retail has confirmed that it will reduce the...
French retailer Auchan experienced a data breach affecting hundreds of thousands of customers, resulting in the theft of personal...
French supermarket giant Auchan has confirmed another significant cyberattack, disclosing on August 21 that the personal data of several...
Auchan confirms that the personal information of hundreds of thousands of customers was stolen in a data breach.
French retail giant Auchan has announced it has fallen victim to another significant cyberattack, marking the second major data breach for...
Major French retail chain Auchan announced on August 21, 2025, that it suffered a significant cybersecurity incident resulting in the...
French retail giant Auchan announced a cyberattack that resulted in the theft of loyalty account information belonging to several hundred...
French supermarket group Auchan has revealed its intention to shut 25 stores throughout Spain and eliminate 710 jobs.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Auchan Retail is http://www.auchan-retail.com.
According to Rankiteo, Auchan Retail’s AI-generated cybersecurity score is 768, reflecting their Fair security posture.
According to Rankiteo, Auchan Retail currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Auchan Retail has not been affected by any supply chain cyber incidents, and no incident IDs are currently listed for the organization.
According to Rankiteo, Auchan Retail is not certified under SOC 2 Type 1.
According to Rankiteo, Auchan Retail does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Auchan Retail is not listed as GDPR compliant.
According to Rankiteo, Auchan Retail does not currently maintain PCI DSS compliance.
According to Rankiteo, Auchan Retail is not compliant with HIPAA regulations.
According to Rankiteo,Auchan Retail is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Auchan Retail operates primarily in the Retail industry.
Auchan Retail employs approximately 59,994 people worldwide.
Auchan Retail presently has no subsidiaries across any sectors.
Auchan Retail’s official LinkedIn profile has approximately 504,249 followers.
Auchan Retail is classified under the NAICS code 43, which corresponds to Retail Trade.
No, Auchan Retail does not have a profile on Crunchbase.
Yes, Auchan Retail maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/auchan.
As of January 24, 2026, Rankiteo reports that Auchan Retail has experienced 1 cybersecurity incidents.
Auchan Retail has an estimated 15,595 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach.
Detection and Response: The company detects and responds to cybersecurity incidents through an incident response plan activated with yes, and law enforcement notified with yes (collaborating with french authorities and law enforcement), and containment measures with breach contained promptly, and remediation measures with accelerated deployment of multifactor authentication (mfa) for internal systems, remediation measures with strengthened network monitoring capabilities, remediation measures with mandatory cybersecurity training for all employees, and recovery measures with complimentary credit monitoring services for affected customers, and communication strategy with official statement released; impacted customers notified; advisory issued for phishing vigilance, and enhanced monitoring with yes (strengthened network monitoring)..
Title: Auchan Cyberattack Results in Theft of Loyalty Account Information
Description: French retail giant Auchan announced on August 21 that it fell victim to a cyberattack resulting in the theft of loyalty account information belonging to several hundred thousand customers. Attackers accessed personal data such as names, postal and email addresses, phone numbers, and loyalty card numbers. Financial data, including bank details, loyalty card PINs, and accrued loyalty balances, remained secure. The breach was promptly detected and contained. Auchan notified impacted customers and reported the incident to the French data protection authority (CNIL). This marks the second significant data breach at Auchan within a year, following a similar attack in November 2024 targeting customer loyalty information.
Date Detected: 2025-08-21
Date Publicly Disclosed: 2025-08-21
Type: Data Breach
Motivation: Data Theft (Likely for phishing or resale on dark web)
Common Attack Types: The most common types of attacks the company has faced is Breach.

Data Compromised: Names, Postal addresses, Email addresses, Phone numbers, Loyalty card numbers
Systems Affected: Loyalty account systems
Operational Impact: Heightened operational pressures, need to restore consumer confidence, and strengthen cybersecurity posture
Brand Reputation Impact: Negative (second breach within a year, eroding consumer trust)
Identity Theft Risk: Moderate (personal data exposed, but no financial or password data compromised)
Payment Information Risk: None (financial data remained secure)
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Personal Identifiable Information (Pii) and .

Entity Name: Auchan
Entity Type: Retail
Industry: Supermarket/Retail
Location: France
Size: Large (one of France’s leading supermarket chains)
Customers Affected: Several hundred thousand

Incident Response Plan Activated: Yes
Law Enforcement Notified: Yes (collaborating with French authorities and law enforcement)
Containment Measures: Breach contained promptly
Remediation Measures: Accelerated deployment of multifactor authentication (MFA) for internal systemsStrengthened network monitoring capabilitiesMandatory cybersecurity training for all employees
Recovery Measures: Complimentary credit monitoring services for affected customers
Communication Strategy: Official statement released; impacted customers notified; advisory issued for phishing vigilance
Enhanced Monitoring: Yes (strengthened network monitoring)
Incident Response Plan: The company's incident response plan is described as Yes.

Type of Data Compromised: Personal identifiable information (pii)
Number of Records Exposed: Several hundred thousand
Sensitivity of Data: Moderate (no financial or password data exposed)
Data Exfiltration: Yes (personal data stolen)
Personally Identifiable Information: NamesPostal addressesEmail addressesPhone numbersLoyalty card numbers
Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: Accelerated deployment of multifactor authentication (MFA) for internal systems, Strengthened network monitoring capabilities, Mandatory cybersecurity training for all employees, .
Handling of PII Incidents: The company handles incidents involving personally identifiable information (PII) through by breach contained promptly.
Data Recovery from Ransomware: The company recovers data encrypted by ransomware through Complimentary credit monitoring services for affected customers, .

Regulatory Notifications: Reported to Commission nationale de l’informatique et des libertés (CNIL)

Lessons Learned: Importance of vigilance against phishing attempts, need for robust cybersecurity measures (e.g., MFA, monitoring, employee training), and proactive customer communication to mitigate reputational damage.

Recommendations: Enhance cybersecurity defenses, particularly for loyalty program databases., Implement stricter access controls and continuous monitoring for unusual activity., Conduct regular security audits and penetration testing., Provide ongoing phishing awareness training for customers and employees., Consider third-party security assessments to identify vulnerabilities.Enhance cybersecurity defenses, particularly for loyalty program databases., Implement stricter access controls and continuous monitoring for unusual activity., Conduct regular security audits and penetration testing., Provide ongoing phishing awareness training for customers and employees., Consider third-party security assessments to identify vulnerabilities.Enhance cybersecurity defenses, particularly for loyalty program databases., Implement stricter access controls and continuous monitoring for unusual activity., Conduct regular security audits and penetration testing., Provide ongoing phishing awareness training for customers and employees., Consider third-party security assessments to identify vulnerabilities.Enhance cybersecurity defenses, particularly for loyalty program databases., Implement stricter access controls and continuous monitoring for unusual activity., Conduct regular security audits and penetration testing., Provide ongoing phishing awareness training for customers and employees., Consider third-party security assessments to identify vulnerabilities.Enhance cybersecurity defenses, particularly for loyalty program databases., Implement stricter access controls and continuous monitoring for unusual activity., Conduct regular security audits and penetration testing., Provide ongoing phishing awareness training for customers and employees., Consider third-party security assessments to identify vulnerabilities.
Key Lessons Learned: The key lessons learned from past incidents are Importance of vigilance against phishing attempts, need for robust cybersecurity measures (e.g., MFA, monitoring, employee training), and proactive customer communication to mitigate reputational damage.
Implemented Recommendations: The company has implemented the following recommendations to improve cybersecurity: Provide ongoing phishing awareness training for customers and employees., Consider third-party security assessments to identify vulnerabilities., Conduct regular security audits and penetration testing., Enhance cybersecurity defenses, particularly for loyalty program databases. and Implement stricter access controls and continuous monitoring for unusual activity..

Source: News Article (Generic Placeholder - Follow for updates on Google News, LinkedIn, X)
Date Accessed: 2025-08-21
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Auchan Official StatementDate Accessed: 2025-08-21, and Source: News Article (Generic Placeholder - Follow for updates on Google News, LinkedIn, X)Date Accessed: 2025-08-21.

Investigation Status: Ongoing (French authorities and Auchan’s IT security teams collaborating to trace the attack’s origin)
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Official statement released; impacted customers notified; advisory issued for phishing vigilance.

Stakeholder Advisories: Customers advised to remain alert for phishing attempts and report suspicious communications.
Customer Advisories: Auchan urged customers to scrutinize unsolicited emails/texts seeking personal/financial details and offered complimentary credit monitoring services.
Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: were Customers advised to remain alert for phishing attempts and report suspicious communications. and Auchan urged customers to scrutinize unsolicited emails/texts seeking personal/financial details and offered complimentary credit monitoring services..

High Value Targets: Loyalty Program Databases,
Data Sold on Dark Web: Loyalty Program Databases,

Corrective Actions: Deployment Of Multifactor Authentication (Mfa) For Internal Systems, Enhanced Network Monitoring, Mandatory Cybersecurity Training For Employees, Complimentary Credit Monitoring For Affected Customers,
Post-Incident Analysis Process: The company's process for conducting post-incident analysis is described as Yes (strengthened network monitoring).
Corrective Actions Taken: The company has taken the following corrective actions based on post-incident analysis: Deployment Of Multifactor Authentication (Mfa) For Internal Systems, Enhanced Network Monitoring, Mandatory Cybersecurity Training For Employees, Complimentary Credit Monitoring For Affected Customers, .
Most Recent Incident Detected: The most recent incident detected was on 2025-08-21.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2025-08-21.
Most Significant Data Compromised: The most significant data compromised in an incident were Names, Postal addresses, Email addresses, Phone numbers, Loyalty card numbers and .
Most Significant System Affected: The most significant system affected in an incident was Loyalty account systems.
Containment Measures in Most Recent Incident: The containment measures taken in the most recent incident was Breach contained promptly.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Loyalty card numbers, Postal addresses, Names, Phone numbers and Email addresses.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 0.
Most Significant Lesson Learned: The most significant lesson learned from past incidents was Importance of vigilance against phishing attempts, need for robust cybersecurity measures (e.g., MFA, monitoring, employee training), and proactive customer communication to mitigate reputational damage.
Most Significant Recommendation Implemented: The most significant recommendation implemented to improve cybersecurity was Provide ongoing phishing awareness training for customers and employees., Consider third-party security assessments to identify vulnerabilities., Conduct regular security audits and penetration testing., Enhance cybersecurity defenses, particularly for loyalty program databases. and Implement stricter access controls and continuous monitoring for unusual activity..
Most Recent Source: The most recent source of information about an incident are News Article (Generic Placeholder - Follow for updates on Google News, LinkedIn, X) and Auchan Official Statement.
Current Status of Most Recent Investigation: The current status of the most recent investigation is Ongoing (French authorities and Auchan’s IT security teams collaborating to trace the attack’s origin).
Most Recent Stakeholder Advisory: The most recent stakeholder advisory issued was Customers advised to remain alert for phishing attempts and report suspicious communications., .
Most Recent Customer Advisory: The most recent customer advisory issued was an Auchan urged customers to scrutinize unsolicited emails/texts seeking personal/financial details and offered complimentary credit monitoring services.
.png)
Typemill is a flat-file, Markdown-based CMS designed for informational documentation websites. A reflected Cross-Site Scripting (XSS) exists in the login error view template `login.twig` of versions 2.19.1 and below. The `username` value can be echoed back without proper contextual encoding when authentication fails. An attacker can execute script in the login page context. This issue has been fixed in version 2.19.2.
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the DomainCheckerApp class within domain/script.js of Sourcecodester Domain Availability Checker v1.0. The vulnerability occurs because the application improperly handles user-supplied data in the createResultElement method by using the unsafe innerHTML property to render domain search results.
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/upload.php component. The application fails to properly validate uploaded file contents. Additionally, the application preserves the user-supplied file extension during the save process. This allows an unauthenticated attacker to upload arbitrary PHP code by spoofing the MIME type as an image, leading to full system compromise.
A UNIX symbolic link following issue in the jailer component in Firecracker version v1.13.1 and earlier and 1.14.0 on Linux may allow a local host user with write access to the pre-created jailer directories to overwrite arbitrary host files via a symlink attack during the initialization copy at jailer startup, if the jailer is executed with root privileges. To mitigate this issue, users should upgrade to version v1.13.2 or 1.14.1 or above.
An information disclosure vulnerability exists in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend platform thru 2025-05-28. This unauthenticated endpoint returns a list of cashier accounts, including names, email addresses, usernames, and passwords hashed using MD5. As MD5 is a broken cryptographic function, the hashes can be easily reversed using public tools, exposing user credentials in plaintext. This allows remote attackers to perform unauthorized logins and potentially gain access to sensitive POS operations or backend functions.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.