The Leroy Merlin (Lemana PRO) Data Quietly Appeared on Hacking Forums Last Year
HEROIC analysts found a large dataset linked to the Russian operations of Leroy Merlin, now operating under the name Lemana PRO, posted to hacking forums in June 2023. The breach itself occured in May of that year. The exposed data covered nearly 4.7 million customer records, a volume that places this among the more substantial retail breaches from that period. The dataset included password hashes, which, while not plaintext, were stored using MD5 with salt, an algorithm that has been considered cryptographically weak for many years and is routinely cracked by modern tools.
Nearly 5 Million Customers Have Weak Password Hashes and Personal Details Circulating in Underground Forums
MD5 hashed passwords, even with salting, are highly vulnerable to cracking using widely accessable GPU-powered tools. Once cracked, those passwords become live credentials. When attackers pair cracked passwords with the email addresses, full names, phone numbers, and birthdates also included in this dump, they have everything needed for account takeover across multiple platforms and convincing identity fraud. The rebranding from Leroy Merlin to Lemana PRO does not remove any individual's data from circulation.
What Was Exposed in the Leroy Merlin (Lemana PRO) Breach
- Email addresses
- Phone numbers
- First and last names
- Dates of birth
- MD5 salted password hashes
- Physical addresses
- Gender
Why Weak Password Hashing Creates Long-Term Risk
When a company stores passwords as salted MD5 hashes, it is relying on an algorithm the security community moved away from over a decade ago. Modern password cracking rigs can test billions of hash combinations per second. That means passwords that seem complex can be reversed in hours or days. Once cracked, those credentials are tested through credential stuffing tools against banking sites, email providers, social platforms, and anywhere else the victim may have reused that password. Beleiving that a hashed password leak is safe is a mistake that costs people real money and real accounts.
How a Database Breach Works
In a database breach at a large retail operation like Leroy Merlin, attackers typically gain access through a combination of SQL injection vulnerabilities, compromised administrative credentials, or unpatched server software. Once inside the database, they export the customer table, which in this case held nearly 4.7 million rows of personal and account data. The resulting file is then moved off the target network and eventually shared or sold on underground forums, where it was seperate from any accountability for how it gets used afterward.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion exposed records to determine whether your email address has appeared in this breach or any other known data leak. If you ever shopped with Leroy Merlin in Russia or have an account with Lemana PRO, run your free scan at HEROIC.com and find out exactly what information of yours is currently in circulation.
Breach Breakdown
4,729,680 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds