> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Leroy Merlin Spain Customer Database of Nearly 55,000 Records Allegedly Leaked
- URL: https://darkwebinformer.com/leroy-merlin-spain-customer-database-of-nearly-55-000-records-allegedly-leaked/
- Published: 2026-06-25T20:34:05.000Z
- Updated: 2026-06-25T20:34:05.000Z
- Author: Dark Web Informer
- Tags: Leaks

Breach Report ![Spain flag](https://flagcdn.com/w40/es.png)Spain Retail 

## Leroy Merlin Spain Customer Database of Nearly 55,000 Records Allegedly Leaked

A threat actor using the alias **Saturne** has posted what they describe as the **customer database of leroymerlin.es**, the official Spanish e-commerce site of Leroy Merlin, a major home-improvement and DIY retail chain. The leak reportedly contains **54,723 records** dated June 2026 and is being shared for free. Per the post, each record includes the customer's name and surname, email address, phone number, **Spanish national ID (DNI)** document type and number, full postal address (street, complement, postal code, city, and province), a Firebase user ID, marketing-consent flags, and store-card and billing references. The dataset's authenticity and scope are **unverified**.

Severity MEDIUM 

Data54,723 records

PriceFree leak

Country![Spain flag](https://flagcdn.com/w40/es.png)Spain

ActorSaturne

### ▣Post details

TargetLeroymerlin.es (Leroy Merlin Spain)

Country![Spain flag](https://flagcdn.com/w40/es.png)Spain

SectorRetail / E-commerce

ClaimCustomer database leaked (54,723 records)

DataNames, emails, phones, DNI, addresses

FreshnessJun 2026

ObservedJun 25, 2026

ActorSaturne

### !Allegedly included

- 54,723 records (claimed)
- Names & surnames
- Email addresses
- Phone numbers
- DNI (Spanish national ID)
- Full postal addresses
- Marketing-consent flags
- Store-card & billing references

### ◱Screenshot

[ ![Leroy Merlin Spain alleged leak Screenshot 1](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/29783659786234987623498763298723.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/size/w1304/format/webp/2026/06/29783659786234987623498763298723.png) 

### ⚠Potential impact

This breach pairs standard contact data with stronger identifiers: alongside names, emails, and phone numbers, the records reportedly include each customer's **Spanish national ID (DNI)** and full home address. The DNI is a core identity document in Spain used across banking, government, and contracts, so its exposure together with a verified home address and contact details creates a meaningful risk of identity theft, fraudulent account opening, and convincing targeted phishing or impersonation referencing real address and purchase details. No passwords or full payment-card numbers appear in the sample, which limits direct account or card compromise, but the national-ID-plus-address combination keeps this above a routine retail email leak. Because the data concerns EU residents, the exposed identifiers and contact details also carry GDPR implications. No customer records, names, IDs, addresses, or download links are reproduced here. The scope and authenticity are unverified.

### iStatus

Unverified 

A sample record and a download were posted to a forum behind a reply-gate; the sample (which contains a customer's personal data), the customers' identifying details, and the actor's contact handle are **not** reproduced here. The actor describes the data as a free leak of the retailer's database. The claim has **not been independently confirmed** and Leroy Merlin has not publicly addressed it.

Want the non-redacted screenshots? **Paid subscribers** get all of the claim details and unredacted screenshots. Check out the [threat feed](https://darkwebinformer.com/threat-feed/) or [ransomware feed](https://darkwebinformer.com/ransomware-feed/) (whichever applies to this post), then after subscribing, search there for this alert to view the unredacted version. [View pricing →](https://darkwebinformer.com/pricing) 

[DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE