Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Cyber Threats » French Gun Retailer Armurerie Lavaux Hit by Cyberattack Exposing Customer Order Data

French Gun Retailer Armurerie Lavaux Hit by Cyberattack Exposing Customer Order Data

Last updated:August 7, 2026
Human Written
  • Leading French gun store Armurerie Lavaux suffered a major cyberattack that exposed order histories for tens of thousands of clients.

  • Stolen files contain names, home addresses, telephone numbers, and product purchases, but financial data and weapon serial numbers remain secure.

  • The company fixed the system vulnerability, notified privacy regulators, and warned buyers to watch out for suspicious physical visits or phishing attempts.

French Gun Retailer Armurerie Lavaux Hit by Cyberattack Exposing Customer Order Data

Armurerie Lavaux recently confirmed a major cyberattack targeting its digital infrastructure. The French company stands as a top seller of hunting equipment, sports shooting supplies, and legal weapons. Security teams noticed unusual network activity before confirming that hackers breached their sales systems.

The security breach allowed unauthorized entities to extract sensitive order history from tens of thousands of buyers. Exfiltrated information contains customers’ full names, home addresses, contact numbers, and precise purchasing logs. Company leaders stated that payment details, passwords, national SIA registration codes, and individual serial numbers remain completely safe.

The company quickly patched the software loop that allowed unauthorized access to its private file server. Management notified affected individuals while warning them to watch out for potential fraudulent schemes.

Extent of Exfiltrated Customer Details and System Boundaries

Hackers gained access to customer sales records dating back across recent transaction periods. The stolen files contain clear personal profiles linking real identities directly to physical home locations. Exfiltrated database tables expose item descriptions, total checkout prices, and exact product part numbers. Criminals can easily read these entries to figure out who bought specific gear. Information about the individuals who possess ammunition or tactical supplies creates certain safety risks for households.

Personal identification information leaked via the breach includes buyer names, valid e-mail addresses, postal addresses, and phone numbers. Order history logs also reveal detailed product descriptions, specific item part numbers, and total spending amounts for each transaction.

Furthermore, company technicians quickly isolated affected network modules to stop any extra exfiltration. The intruder did not reach banking systems or core encryption vaults containing private account passwords. The financial data – including bank accounts and credit card numbers remained safe during the breach. Official gun registers, SIA numbers, login passwords, and firearm serial records also stayed secure. 

Instead, the attack affected external order logs kept for fulfillment processing. The executives of the organization have reported to regulators dealing with data protection in France (CNIL). Experts in security are currently conducting an investigation to examine the logs of the systems and trace how the breach took place.

In a separate incident, an Akira ransomware affiliate also used legitimate services for data exfiltration, accessing a hypervisor to create a new virtual machine, disabling Microsoft Defender, and using LimeWire’s Easyupload.io platform to exfiltrate stolen data before deploying ransomware.

This incident creates unusual physical risks that go well beyond standard online identity theft. Criminals holding precise addresses paired with weapons purchases might attempt targeted home burglaries.

Additionally, this attack marks another troubling security event impacting the French firearms community. Earlier security incidents exposed sensitive information inside the national weapon register system, known officially as the Système d’Information sur les Armes. Similar leaks previously targeted the French Shooting Federation, showing a clear pattern of attacks against sports shooters.

Security analysts keep an eye on the dark web forums where hackers traffic stolen databases. Bad dealers frequently mix numerous previously published lists to create extremely detailed target maps.

The crime syndicates can use location data of weapons because stolen weaponry can be traded at high prices in the black market. Store owners advised customers who bought Category B, C, or D gear to stay alert. They asked users to contact local law enforcement immediately if strange visitors appear near their properties.

Required Protective Steps and Remediation Actions

Armurerie Lavaux sent personalized email alerts to every client listed in the compromised sales logs. The company outlined specific safety recommendations to help buyers defend against follow-up scams.

Consequently, security specialists urge affected buyers to watch out for incoming telephone calls and suspicious messages. Fraudsters often use stolen order histories to sound convincing during social engineering attempts. A scammer might pretend to represent a delivery service or gun store to steal more credentials.

Affected persons should not click on any strange email links or give out confirmation numbers over the phone. Meanwhile, the retailer pointed out that the breach did not compromise user passwords – this means customers don’t have to reset main account passwords on the store site. The store management has adopted new firewall rules and applied additional tracking programs on all of the operating servers.

Moreover, the legal professionals lodged official criminal grievances with the public prosecutors to assist law enforcement in their inquiries. The authorities are in constant contact with the cyber professionals to establish the identities of the hackers.

As such, it is essential for gun owners in France to be careful at a time when companies are strengthening their cybersecurity. Businesses managing sensitive sales records face continuous threats from organized hacking groups. Stronger access controls and strict data minimization practices are vital to protecting physical customer safety.

Share this article

About the Author

Memchick E

Memchick E

Digital Privacy Journalist

Memchick is a digital privacy journalist who investigates how technology and policy impact personal freedom. Her work explores surveillance capitalism, encryption laws, and the real-world consequences of data leaks. She is driven by a mission to demystify digital rights and empower readers with the knowledge to protect their anonymity online.

View all posts by Memchick E >
Comments (0)

No comments.