Menu
Browse

Cyber Incident Victim: leroymerlin.ru

Date:

Mar 2022

Location:

Russia

Summary

The website of a major home improvement retailer operating in Russia was disrupted by a DDoS attack conducted by the hacktivist group Anonymous. This offensive targeted companies continuing business operations in Russia, resulting in temporary unavailability of the victim's Russian online presence. The attack formed part of a broader campaign against Western corporations maintaining activities in the region, with Anonymous simultaneously targeting other multinational retailers' Russian digital assets. The group publicly demonstrated the impact through website outage evidence as part of their coordinated actions against entities perceived as financially supporting Russia through continued commercial engagement.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

Anonymous, a decentralized hacktivist collective, initiated cyber operations against Russian entities following the Russian invasion of Ukraine on February 24, 2022. The group expanded its targeting in March 2022 to include Western companies maintaining business operations in Russia, asserting these organizations financially supported the Russian government through tax payments. The collective publicly threatened companies continuing operations in Russia, framing their actions as retaliation for enabling the Russian war effort. Nestlé was the first confirmed target of this campaign, with Anonymous claiming theft of 10 GB of sensitive data including corporate emails, passwords, and business customer information. The group leaked a sample dataset containing over 50,000 Nestlé business customers as proof of compromise.

Cyber Incident Image

On March 24, 2022, Anonymous escalated operations by launching distributed denial-of-service (DDoS) attacks against the Russian websites of multinational retailers Auchan, Leroy Merlin, and Decathlon. These coordinated attacks rendered the targeted domains, including leroymerlin.ru, inaccessible to users. The collective’s affiliated Twitter account, Anonymous TV, publicly claimed responsibility for the outages and provided screenshots as evidence of the websites’ non-functionality. Concurrently, Anonymous announced a separate breach of the Central Bank of Russia, exfiltrating 35,000 files with a threat to release the data within 48 hours. The DDoS attacks caused immediate disruption to the targeted companies’ Russian online services, though the duration of outages and technical specifics of remediation efforts were not disclosed in available reporting. No data breach claims or evidence of network infiltration specific to Leroy Merlin were asserted beyond the confirmed website disruption.

Sources
Sources available to members
1 source