Was anything learned from the previous incident?
Harrods blames its supplier after crims steal 430k customers’ data in fresh attack
Luxury London-based retailer Harrods is facing its second cybersecurity scandal in 2025, confirming criminals not only stole 430,000 customers' data in a fresh attack but have even made contact. It began notifying affected customers on September 26 that their data was taken during a break-in at one of its suppliers. Harrods …
COMMENTS
-
-
Monday 29th September 2025 13:56 GMT Anonymous Coward
What’s the betting it’s something they outsourced and it’s now come back to bite them on their large backside. I visited the store a few days after the first attempt and I didn’t notice anything different, so maybe that one wasn’t bad, like Harrods claimed it wasn’t and they caught the intrusion.
-
-
Monday 29th September 2025 20:03 GMT MachDiamond
Why the data migration
If a 3rd party company has access to sensitive data, that should come with company ending risk on both sides. Too bad for Harrods, but they chose to trust the information to somebody else rather than look after it themselves. The question always needs to be asked whether storing certain data is necessary in the first place. Obviously, they think it has value. They should think of it in the same way as a tank farm that stores petrol. There's value there, but also risk that has to be constantly mitigated. If they don't look after it, boom and thanks for playing. Insert more coins to play again.
-
Wednesday 1st October 2025 11:45 GMT Taliesinawen
Blame the Outsourcer and SQL Injection /s
How would a compromise of a third-party supplier's system give the hackers access to Harrods customers' data.
“Attackers used exploitation techniques like SQL Injection to gain unauthorized access and attempted extortion.”