Egidio
Case file Β· August 21, 2026

TERVEO: confirmed, site rebuilt and relaunched within a week

E-commerce retailer TERVEO confirmed an intrusion between July 19 and 25, 2026. The site was taken offline immediately, entirely rebuilt on a new server, and relaunched within days. No payment data is affected.

⚠️ Confirmed directly by the company. TERVEO published its own incident page, with a rare level of detail: precise dates, data affected by customer profile, and technical steps taken. This is one of the most transparent cases documented on this site.

The numbers

Jul 19-25
Intrusion window confirmed by TERVEO on terveo.com.
TERVEO incident page, July 30-31, 2026.
Jul 28
Date the site relaunched, entirely rebuilt on a new server after being taken offline as soon as the intrusion was discovered.
TERVEO incident page.
0
Payment data affected, in any case β€” payment is processed directly through BNP Paribas and PayPal, never through TERVEO's servers.
TERVEO incident page.
3
Customer categories affected, each with a different data scope: customers who ordered, newsletter subscribers, contact-form inquiries.
TERVEO incident page.

Timeline

CONFIRMED
July 19-25, 2026
An unauthorized third party accesses information stored on terveo.com during this window.
CONFIRMED
Discovery
The site is taken offline immediately upon discovery, then entirely rebuilt on a new server. All customer passwords are reset, technical access credentials renewed.
CONFIRMED
July 28, 2026
The site relaunches on its new infrastructure.
CONFIRMED
July 30-31, 2026
TERVEO notifies its customers by email and publishes its detailed incident page. The CNIL is informed.

🧭A rare level of detail

This case stands out for its transparency: instead of a vague statement, TERVEO published a dedicated page precisely distinguishing which data leaked by customer profile β€” a customer who placed an order doesn't have the same exposed scope as a mere newsletter subscriber. This granularity lets everyone know exactly what to watch for, instead of guessing from a single global figure.

What it changes for you

If you ordered from TERVEO, your name, email, and depending on your case your phone number, address and order history may have leaked. The main risk is a phishing email citing a real order (sauna, cold bath) to appear legitimate. See From Leak to Scam.

πŸ”’ Your credentials have already been reset by TERVEO β€” if you received an email asking you to "confirm your password" on this site, that would be suspicious, since the step was already taken proactively.

Frequently asked questions

Is the TERVEO incident confirmed?

Yes, directly by the company itself, via a detailed dedicated page.

What data is affected?

Depending on customer profile: name/email for all, phone/address/order history for buyers, contact messages for newsletter subscribers.

Is my payment data affected?

No, in any case: payment goes through BNP Paribas and PayPal, never through TERVEO's servers.

πŸ“Œ Last checked: August 21, 2026. Verifiable information to report: contact@egidio.app.

Related reading

Cite this page Egidio β€” The Threat Laboratory, "TERVEO: confirmed, site rebuilt and relaunched within a week," egidio.app/en/laboratoire/terveo-ecommerce-breach/. Licensed CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.