Cabinet Kohen Avocats · Paris

—

Maître Reda KOHEN intervient en droit immobilier, droit des sociétés et droit des affaires à Paris. Première analyse : 80 € TTC, réponse personnelle sous 24 heures.

100 % confidentiel · Secret professionnel · Sans engagement

Article généré par une intelligence artificielle, selon un processus conçu et contrôlé par le cabinet

Source : Cour de cassation – Base Open Data « Judilibre » & « Légifrance ».

Barreau de Paris Immobilier, sociétés, affaires Fiche CNB avocat.fr
Maître Reda KOHEN, avocat au Barreau de Paris
Maître Reda KOHEN
Avocat au Barreau de Paris

Has ASOS Been Hacked? Snowflake Breach Claim, Hack Notification and Rights of Customers in France

On 6 October 2026, users of the ASOS mobile app received a push notification titled “Asos hacked” which claimed that the online fashion retailer’s data had been “fully compromised” through its Snowflake instance and directed readers to a Telegram channel, according to reports published the same day by the BBC, The Guardian and The Times. The retailer’s share price fell by more than 14 percent on the London Stock Exchange, while its website and app continued to operate. The company stated that it was aware of the reports and was still investigating whether any intrusion had actually taken place. No official source had, at the time of writing, confirmed an intrusion, a leak of customer data or any harm to account holders, and no liability has been established; only a court can decide such questions, and the contracts signed between the retailer and its customers prevail over any general analysis. The developments below are general in scope: they describe the practical and legal checks that are useful for any customer in France who receives such a notification, and they do not describe the situation of any particular company.

French customers are directly concerned because the retailer sells and delivers in France through its French-language storefront, so the personal data of customers residing in France is processed under Regulation (EU) 2016/679, the General Data Protection Regulation, alongside French criminal law. This article therefore answers two questions in order: what is known about the notification of 6 October 2026 and what to do immediately, then which remedies exist in France, from the complaint before the CNIL to compensation and the criminal complaint (plainte).

I. Has ASOS been hacked? What the notification of 6 October 2026 shows

A. What is the “ASOS hacked” Snowflake notification reported by the press?

According to The Guardian, thousands of customers received a notification titled “Asos hacked” with a link sending them to the Telegram messaging service, and the message read: “Dear Asos DPO (data protection officer) and IT, we have fully compromised the Snowflake instance.” The acronym DPO designates the délégué à la protection des données (data protection officer), the person whom the regulation requires large controllers to appoint as a contact point for data protection matters. The BBC reported app users describing a “concerning” pop-up message apparently coming from hackers, and The Times described app customers receiving an alert suggesting a data breach. These three national outlets agree on the core facts: a message was genuinely pushed through the retailer’s own app notification channel, it asserted a total compromise of a Snowflake environment, and it invited the company’s data protection and IT teams to negotiate failing which data would be leaked.

Snowflake, as described in the same press reports, is a cloud platform used to store, process and analyse data, including transactions and demographic information such as clothing sizes and body measurements, and it also enables push notifications to customers’ phones. The fact that the message travelled through the app’s own notification system is what makes the episode worrying from a technical point of view: Dray Agha, senior manager of security operations at Huntress, an online security firm, is quoted as saying that Snowflake is a large cloud database where retailers typically store sensitive customer information and that the push notification suggests the attackers may also have reached the systems controlling the mobile app. That assessment remains an assessment, not a finding: at the time of writing, it is not established by any official source that customer data was accessed, copied or published, and the retailer itself has not confirmed any of the claims.

The link in the message reportedly directed customers to a Telegram channel operated by an apparent group calling itself Xuanye. According to the press reports, threat researchers stated that they had never heard of that group on hacker forums or other Telegram channels, and one researcher quoted observed that new groups often wait for what they regard as a significant opportunity before announcing themselves so as to enter the ecosystem with credibility. In other words, the name behind the claim is unknown to the threat researchers who track extortion groups, which calls for caution in two directions: the claim may understate a real intrusion, or it may overstate access that the authors do not actually have. Customers should therefore treat the notification as a serious warning signal without treating the alleged compromise as a proven fact.

The episode follows a series of cyber incidents affecting British retailers in 2025, recalled by The Guardian: Marks and Spencer, which had to close its website for several weeks, the Co-op, and Harrods. That context explains the market reaction, with the retailer’s shares diving more than 14 percent during the day, but a share price movement proves nothing about the underlying facts. For a customer residing in France, the useful conclusion at this stage is narrow: a message asserting a compromise was pushed through the retailer’s app on 6 October 2026, the national press reported it with the company’s acknowledgment that it was investigating, and everything beyond that, including whether French customers’ data is affected, remains conditional.

B. Has the retailer confirmed a data breach, and what should customers in France do right now?

The short answer is no. According to The Guardian, the retailer said it was aware of the reports of a hack but did not confirm or comment further, and it is understood that it was still investigating whether any hack had taken place while the website and app appeared to continue operating normally on the morning of 6 October 2026. Several elements weigh in the company’s favour and must be stated plainly: the online store and the app stayed online, no category of allegedly affected data has been confirmed by any official source, no sample of customer data has been authenticated in the reports available at the time of writing, and the authors of the message remain unidentified. None of this rules out a real incident, since investigations of this kind take time, but none of it establishes one either.

The most immediate danger for customers, including those in France, does not come from the alleged intrusion itself but from what follows such publicity. Marijus Briedis, chief technology officer at the online service provider NordVPN, is quoted in the press warning customers to watch what happens next, because high-profile cyber incidents create ideal conditions for phishing attacks in which criminals send emails and text messages claiming to be from the retailer, asking the recipient to reset a password, confirm payment details, check an order or claim a refund. That warning applies with full force to French customers: any message received in the coming days that invokes the incident to request credentials, bank details or a payment should be regarded as suspect by default, even when it displays the retailer’s logo and correct order references.

Five practical steps are advisable without delay. First, do not click the link in the suspicious notification and do not join the Telegram channel it promotes; opening such channels exposes the visitor to further malicious content and weakens any later evidential record. Second, change the password of the retailer’s account, choosing a password used nowhere else, and activate multi-factor authentication if the account offers it, since credential reuse is the main way in which one incident becomes several. Third, keep dated evidence: screenshots of the notification as received on the phone, the time of receipt, the state of the account, and any subsequent suspicious message, because French courts and the CNIL both require proof of concrete facts rather than general assertions. Fourth, monitor bank statements and payment instruments linked to online purchases over the coming weeks, and use the opposition procedures of the card issuer at the first unexplained debit. Fifth, check the account’s order history and personal details for any modification the holder did not make, and report any anomaly to the retailer in writing so that a dated record exists. These steps cost nothing, preserve rights, and remain useful whatever the investigation eventually concludes.

II. What rights do customers in France have after a breach notification?

A. Must the company notify the CNIL within 72 hours, and how does a customer complain in France?

European law places the first obligation on the controller, not on the customer. Article 33, paragraph 1, of Regulation (EU) 2016/679 provides that “En cas de violation de données à caractère personnel, le responsable du traitement en notifie la violation en question à l’autorité de contrôle compétente conformément à l’article 55, dans les meilleurs délais et, si possible, 72 heures au plus tard après en avoir pris connaissance, à moins que la violation en question ne soit pas susceptible d’engendrer un risque pour les droits et libertés des personnes physiques. Lorsque la notification à l’autorité de contrôle n’a pas lieu dans les 72 heures, elle est accompagnée des motifs du retard.” (“In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.”) (CNIL guide on personal data breaches: notification within 72 hours). The 72-hour period therefore runs from the moment the controller becomes aware of the breach, and any late notification must explain the delay. The controller must also document the breach, its effects and the remedial measures so that the supervisory authority can verify compliance.

Where the breach is likely to create a high risk for individuals, the controller must also warn the customers themselves. Article 34, paragraph 1, of the same regulation states that “Lorsqu’une violation de données à caractère personnel est susceptible d’engendrer un risque élevé pour les droits et libertés d’une personne physique, le responsable du traitement communique la violation de données à caractère personnel à la personne concernée dans les meilleurs délais.” (“When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.”) (CNIL guide: informing the individuals concerned). Paragraph 2 adds that “La communication à la personne concernée visée au paragraphe 1 du présent article décrit, en des termes clairs et simples, la nature de la violation de données à caractère personnel et contient au moins les informations et mesures visées à l’article 33, paragraphe 3, points b), c) et d).” (“The communication to the data subject referred to in paragraph 1 of this Article shall describe in clear and plain language the nature of the personal data breach and contain at least the information and measures referred to in Article 33(3), points (b), (c) and (d).”) In practice, a customer in France who received the push notification but no individual breach notice should not conclude that nothing happened: the duty to inform each person arises only above the high-risk threshold, and the assessment belongs first to the controller under the control of the supervisory authority, which may order the controller to notify the individuals concerned.

That supervisory authority, for a customer residing in France, is the CNIL, the Commission nationale de l’informatique et des libertés. The regulation gives each authority broad powers: Article 58 provides that “Chaque autorité de contrôle dispose de tous les pouvoirs d’enquête suivants” (“Each supervisory authority shall have all of the following investigative powers”), including the power to put the controller on notice of an alleged violation of the regulation (CNIL guide on personal data breaches). The CNIL publishes a guide on personal data breaches and operates an online breach-notification service for controllers (CNIL guide on personal data breaches; CNIL online service for notifying a personal data breach). Customers cannot use that service themselves, since it is reserved for controllers and processors, but its existence shows where the retailer’s notification, if any, will be examined.

The customer’s own procedural path is the individual complaint, the réclamation. Article 77, paragraph 1, of the regulation provides that “Sans préjudice de tout autre recours administratif ou juridictionnel, toute personne concernée a le droit d’introduire une réclamation auprès d’une autorité de contrôle, en particulier dans l’État membre dans lequel se trouve sa résidence habituelle, son lieu de travail ou le lieu où la violation aurait été commise, si elle considère que le traitement de données à caractère personnel la concernant constitue une violation du présent règlement.” (“Without prejudice to any other administrative or judicial remedy, every data subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the data subject considers that the processing of personal data relating to him or her infringes this Regulation.”) (Article 77 of Regulation (EU) 2016/679). A customer residing in France may therefore complain to the CNIL, which must keep the complainant informed of the progress and outcome of the complaint, and the complaint can be filed through the CNIL’s online complaints service (CNIL online complaints service).

A well-built complaint file contains the account identifier, the dates and screenshots of the notification, any individual notice received from the controller, the written report sent to the retailer, and a precise description of any concrete consequence already observed, such as phishing messages, account modifications or unexplained debits. This discipline matters because the CNIL examines thousands of complaints and prioritises files that demonstrate a verifiable fact pattern. A similar method was described for French customers affected by an earlier breach of a national training body, where complaint, evidence preservation and compensation paths were presented together (what to do after personal data theft affecting a French organisation: complaint, evidence and compensation). The complaint before the CNIL does not require the customer to prove the full technical chain of the intrusion; it requires the customer to show, documents in hand, why the processing of data relating to him or her appears to infringe the regulation.

B. Can a customer in France obtain compensation and file a criminal complaint?

Compensation is possible but never automatic, and French courts apply this rule strictly. Article 82, paragraph 1, of the regulation provides, in the words recalled by the Cour de cassation, “Aux termes de ce texte, toute personne ayant subi un dommage matériel ou moral du fait d’une violation du présent règlement a le droit d’obtenir du responsable du traitement ou du sous-traitant réparation du préjudice subi.” (“Any person who has suffered material or non-material damage as a result of an infringement of this Regulation shall have the right to receive compensation from the controller or processor for the damage suffered.”) (Cour de cassation, chambre sociale, 24 June 2026, no. 24-22.792, recalling Article 82 of Regulation (EU) 2016/679). The key words are damage suffered: the infringement alone is not enough, and the victim must establish a concrete material or moral prejudice (préjudice matériel ou moral), such as financial loss, loss of time and steps taken, anxiety linked to the exposure of sensitive data, or misuse of the data.

The Cour de cassation confirmed this reading in a published judgment of 24 June 2026. Its headnote states that “La violation du règlement (UE) 2016/679 du Parlement européen et du Conseil du 27 avril 2016, relatif à la protection des personnes physiques à l’égard du traitement des données à caractère personnel et à la libre circulation de ces données (RGPD) n’ouvre pas, à elle seule, droit à réparation” (“Infringement of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR) does not, on its own, give rise to a right to compensation”) (Cour de cassation, chambre sociale, 24 June 2026, no. 24-22.792, published in the Bulletin). Quashing a Paris appeal ruling that had treated non-compliance as necessarily causing harm, the Court held: “En statuant ainsi, alors que la simple violation du règlement général sur la protection des données n’ouvre pas, à elle seule, droit à réparation et qu’il lui appartenait d’apprécier si le salarié établissait que la violation de ce règlement qu’elle avait constatée avait causé au salarié un dommage matériel ou moral, la cour d’appel a violé le texte susvisé.” (“In ruling as it did, whereas the mere infringement of the General Data Protection Regulation does not, on its own, give rise to a right to compensation, and whereas it was for the court to assess whether the employee established that the infringement of that regulation which it had found had caused the employee material or non-material damage, the court of appeal infringed the above provision.”)

The same judgment recalls the two reference rulings of the Court of Justice of the European Union. In its judgment of 4 May 2023, Österreichische Post, case C-300/21, the Court of Justice held that “la simple violation des dispositions de ce règlement ne suffit pas pour conférer un droit à réparation” (“the mere infringement of the provisions of that regulation is not sufficient to confer a right to compensation”), while opposing “une règle ou une pratique nationale subordonnant la réparation d’un dommage moral, au sens de cette disposition, à la condition que le préjudice subi par la personne concernée ait atteint un certain degré de gravité” (“a national rule or practice making compensation for non-material damage, within the meaning of that provision, subject to the condition that the damage suffered by the data subject has reached a certain degree of seriousness”) (CJEU, 4 May 2023, Österreichische Post, C-300/21; holdings recalled in Cour de cassation, chambre sociale, 24 June 2026, no. 24-22.792). In its judgment of 25 January 2024, MediaMarktSaturn, case C-687/21, the Court added that financial redress under Article 82 “doit permettre de compenser intégralement le préjudice concrètement subi du fait de la violation de ce règlement, et non une fonction punitive” (“must make it possible to compensate in full the damage actually suffered as a result of the infringement of that regulation, and does not have a punitive function”), and that “la personne demandant réparation au titre de cette disposition est tenue d’établir non seulement la violation de dispositions de ce règlement, mais également que cette violation lui a causé un dommage matériel ou moral” (“a person seeking compensation under that provision is required to establish not only the infringement of provisions of that regulation, but also that that infringement caused him or her material or non-material damage”) (CJEU, 25 January 2024, MediaMarktSaturn, C-687/21). For a customer in France, the practical consequence is direct: keep every piece of evidence of real harm, because a court will award nothing on the sole ground that a breach may have occurred.

French domestic law provides the general fault-based complement to the European compensation right. Article 1240 of the Civil Code states that “Tout fait quelconque de l’homme, qui cause à autrui un dommage, oblige celui par la faute duquel il est arrivé à le réparer.” (“Any act whatever of man which causes damage to another obliges the person by whose fault it occurred to repair it.”) (Article 1240 of the French Civil Code, in force on 6 October 2026). A customer who proves a fault in the handling of personal data, a concrete damage and a causal link may therefore also rely on this general provision before the French courts, in addition to Article 82 of the regulation.

Where to sue is settled in the customer’s favour. Article 79 of the regulation provides that “Sans préjudice de tout recours administratif ou extrajudiciaire qui lui est ouvert, y compris le droit d’introduire une réclamation auprès d’une autorité de contrôle au titre de l’article 77, chaque personne concernée a droit à un recours juridictionnel effectif si elle considère que les droits que lui confère le présent règlement ont été violés du fait d’un traitement de ses données à caractère personnel effectué en violation du présent règlement.” (“Without prejudice to any available administrative or non-judicial remedy, including the right to lodge a complaint with a supervisory authority pursuant to Article 77, each data subject shall have the right to an effective judicial remedy where he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of his or her personal data in non-compliance with this Regulation.”), and that “Toute action contre un responsable du traitement ou un sous-traitant est intentée devant les juridictions de l’État membre dans lequel le responsable du traitement ou le sous-traitant dispose d’un établissement. Une telle action peut aussi être intentée devant les juridictions de l’État membre dans lequel la personne concernée a sa résidence habituelle, sauf si le responsable du traitement ou le sous-traitant est une autorité publique d’un État membre agissant dans l’exercice de ses prérogatives de puissance publique.” (“Proceedings against a controller or a processor shall be brought before the courts of the Member State where the controller or processor has an establishment. Alternatively, such proceedings may be brought before the courts of the Member State where the data subject has his or her habitual residence, except where the controller or processor is a public authority of a Member State acting in the exercise of its public powers.”) (Article 79 of Regulation (EU) 2016/679). A customer habitually resident in France, including in Paris and the Île-de-France region, may therefore bring the compensation claim before the French courts of the domicile, without having to sue abroad.

The criminal path runs in parallel and belongs to the public prosecutor, but it starts with the victim’s complaint, the plainte. French criminal law punishes the intrusion itself: Article 323-1 of the Criminal Code provides that “Le fait d’accéder ou de se maintenir, frauduleusement, dans tout ou partie d’un système de traitement automatisé de données est puni de trois ans d’emprisonnement et de 100 000 € d’amende. Lorsqu’il en est résulté soit la suppression ou la modification de données contenues dans le système, soit une altération du fonctionnement de ce système, la peine est de cinq ans d’emprisonnement et de 150 000 € d’amende.” (“Fraudulently accessing or remaining in all or part of an automated data processing system is punished by three years’ imprisonment and a fine of 100,000 euros. Where this has resulted in either the deletion or modification of data contained in the system, or an alteration of the functioning of that system, the penalty is five years’ imprisonment and a fine of 150,000 euros.”) (Article 323-1 of the French Criminal Code, in force on 6 October 2026). The subsequent handling of the data is also punishable: Article 323-3 punishes “Le fait d’introduire frauduleusement des données dans un système de traitement automatisé, d’extraire, de détenir, de reproduire, de transmettre, de supprimer ou de modifier frauduleusement les données qu’il contient est puni de cinq ans d’emprisonnement et de 150 000 € d’amende.” (“Fraudulently introducing data into an automated processing system, or fraudulently extracting, holding, reproducing, transmitting, deleting or modifying the data it contains, is punished by five years’ imprisonment and a fine of 150,000 euros.”) (Article 323-3 of the French Criminal Code, in force on 6 October 2026).

Two further provisions commonly apply to the aftermath of a breach affecting customers. Article 226-18 of the Criminal Code states that “Le fait de collecter des données à caractère personnel par un moyen frauduleux, déloyal ou illicite est puni de cinq ans d’emprisonnement et de 300 000 euros d’amende.” (“Collecting personal data by fraudulent, unfair or unlawful means is punished by five years’ imprisonment and a fine of 300,000 euros.”) (Article 226-18 of the French Criminal Code, in force on 6 October 2026). And where the stolen data is used to deceive customers, Article 313-1 punishes fraud, defined as “le fait, soit par l’usage d’un faux nom ou d’une fausse qualité, soit par l’abus d’une qualité vraie, soit par l’emploi de manoeuvres frauduleuses, de tromper une personne physique ou morale et de la déterminer ainsi, à son préjudice ou au préjudice d’un tiers, à remettre des fonds, des valeurs ou un bien quelconque, à fournir un service ou à consentir un acte opérant obligation ou décharge. L’escroquerie est punie de cinq ans d’emprisonnement et de 375 000 euros d’amende.” (“the act, whether by the use of a false name or a false capacity, or by the abuse of a genuine capacity, or by the use of fraudulent manoeuvres, of deceiving a natural or legal person and thereby inducing that person, to his or her prejudice or to the prejudice of a third party, to hand over funds, valuables or any property, to provide a service or to consent to an act creating an obligation or a discharge. Fraud is punished by five years’ imprisonment and a fine of 375,000 euros.”) (Article 313-1 of the French Criminal Code, in force on 6 October 2026). A victim residing in Paris may file the plainte at the local commissariat, before the gendarmerie, or by letter to the public prosecutor (procureur de la République), attaching the screenshots, the account records and any phishing message received afterwards. No office may turn the victim away: Article 15-3 of the Code of Criminal Procedure states that “Les officiers et agents de police judiciaire sont tenus de recevoir les plaintes déposées par les victimes d’infractions à la loi pénale, y compris lorsque ces plaintes sont déposées dans un service ou une unité de police judiciaire territorialement incompétents.” (“Officers and agents of the judicial police are required to receive complaints filed by victims of criminal offences, including where those complaints are filed with a judicial police service or unit that lacks territorial jurisdiction.”) (Article 15-3 of the French Code of Criminal Procedure, in force on 6 October 2026). If the prosecutor decides not to prosecute, or if three months pass without a response, the victim may escalate: Article 85 of the same code provides that “Toute personne qui se prétend lésée par un crime ou un délit peut en portant plainte se constituer partie civile devant le juge d’instruction compétent en application des dispositions des articles 52, 52-1 et 706-42 .” (“Any person claiming to have suffered harm as a result of a felony or misdemeanour may, by filing a complaint, become a civil party before the competent investigating judge pursuant to Articles 52, 52-1 and 706-42.”) (Article 85 of the French Code of Criminal Procedure, in force on 6 October 2026).

Conclusion

On the facts available on 6 October 2026, a threatening notification was pushed through the retailer’s own app, the national press reported it, the company stated that it was aware of the reports and was investigating, and the store and app remained online. At the time of writing, no intrusion, no data leak and no damage have been established by any official source, and no liability has been established against anyone; the general terms and privacy documents accepted by each customer prevail over any general analysis, and only a court, criminal or civil, can characterise the facts and allocate responsibility. Within those limits, customers in France hold three levers: immediate self-protection against phishing and credential reuse, the complaint before the CNIL in the State of residence with a documented file, and, where concrete harm is proven, the compensation claim before the French courts with a criminal complaint in support. The Cour de cassation’s message of June 2026 governs the last of these levers: an infringement alone compensates nothing, while proven harm, even moral harm without a threshold of seriousness, is compensated in full. Evidence gathered from the first day therefore decides everything that follows.

Source : Cour de cassation – Base Open Data « Judilibre » & « Légifrance ».

What our clients say

4,9269 Google reviews
Share your review
kader ladjouzi
2 weeks ago

Best real estate and business lawyer in Paris. A compassionate and attentive lawyer, with a wonderful team. Thank you, Maître KOHEN

Translated from French

Janou SAMUEL
1 month ago

Thank you to Maître KOHEN for his analyses of recent case law regarding fraudulent concealment in real estate sales. This reinforces my decision to pursue an action for rescission that I am considering after acquiring a house affected by serious defects intentionally concealed by the seller and not reported by the real estate agent; also defects (rising damp) characterized by progressive through-cracks and damp patches, not reported by the real estate agent… Worse, defects concealed by the latter or on his initiative under a coat of paint and polystyrene tiles glued to the ceiling of a bedroom. And said real estate agent was the drafter of the preliminary contract, which naturally contains no information regarding any of these defects. I would just add that, being 77 years old and suffering from cognitive impairment, I am certain the real estate agent thought I would not be able to uncover the deception and, above all, characterize fraudulent intent, let alone initiate legal proceedings given the complexity and length of the process... That is why I am opting for criminal proceedings, insofar as the intentional concealment of defects by the seller and then by the real estate agent

Translated from French

Paul MALIK (powlo)
4 months ago

Maître Reda KOHEN assisted me in a dispute concerning a sale agreement with a defaulting party. He provided professional and responsive support, and I highly recommend him.

Translated from French

Reply from the firm

Legal advice is only valuable if it arrives on time — delighted to have been there when needed. Thank you for your kind words.

Rayan Kallout
5 months ago

I highly recommend Maître Reda Kohen. Thanks to his explanations, I was able to recover my security deposit in a situation that seemed blocked. He was responsive, clear, and very professional. A big thank you for his invaluable help!

Translated from French

Reply from the firm

The return of the security deposit is a more common rental dispute than one might think; glad that the situation was resolved quickly. Thank you for this feedback.

Naji Jouahri
5 months ago

Excellent support from Maître Kohen in a case combining business law and real estate law. Clear legal analysis from the first meeting, right through to the hearing. Professional and accessible lawyer, I highly recommend his firm in Paris 17.

Translated from French

Reply from the firm

Cases at the intersection of business law and real estate law require a comprehensive overview — that's the core of the firm's practice, from the initial meeting to the hearing. Thank you for this precise recommendation.

Halim Tunde
5 months ago

Maître Kohen assisted me in recovering unpaid debts from a defaulting tenant. Procedure mastered from start to finish, from the payment order to eviction. Human, attentive, and always reachable. Thank you for your work.

Translated from French

Reply from the firm

Collecting unpaid rent requires a procedure handled from start to finish, without downtime — glad to have seen yours through to completion. Thank you for this testimonial.

Cha
5 months ago

As a young student living in an apartment, my landlord tried to make me leave my accommodation even though he had sent me no termination notice. I therefore contacted Mr. Reda Kohen to help me as I couldn’t handle the situation alone. In just 3 days everything was resolved, Maître Kohen defended me and accompanied me with an irreproachable level of commitment and efficiency. I can only recommend his professionalism!

Translated from French

Reply from the firm

An irregular termination notice does not terminate a lease: delighted that the situation was resolved in a few days. Good luck with your studies.

Asmaa Maazaz
6 months ago

I turned to Maître Kohen for a complex real estate dispute and I highly recommend his firm. He is very professional; he thoroughly analyzed my case from the very first appointment and clearly explained the possible options. Thanks to his expertise, we achieved a very favorable outcome. Responsive, a good teacher, and committed, he is a lawyer you can truly trust. Yours faithfully, Miss Maazaz

Translated from French

Reply from the firm

Thank you very much, Miss Maazaz, for this feedback. Analytical rigor and responsiveness are essential commitments of our law firm specializing in real estate law in Paris, where each case requires a tailored approach. Delighted that we were able to achieve a favorable outcome. The firm remains at your disposal. Best regards.