The Register Home Page

back to article Harrods blames its supplier after crims steal 430k customers’ data in fresh attack

Luxury London-based retailer Harrods is facing its second cybersecurity scandal in 2025, confirming criminals not only stole 430,000 customers' data in a fresh attack but have even made contact. It began notifying affected customers on September 26 that their data was taken during a break-in at one of its suppliers. Harrods …

  1. Doctor Syntax Silver badge

    Was anything learned from the previous incident?

    1. Anonymous Coward
      Anonymous Coward

      Nah

      No impact on important people and we have someone who will take the blame so carry on.

    2. Anonymous Coward
      Anonymous Coward

      What’s the betting it’s something they outsourced and it’s now come back to bite them on their large backside. I visited the store a few days after the first attempt and I didn’t notice anything different, so maybe that one wasn’t bad, like Harrods claimed it wasn’t and they caught the intrusion.

  2. VoiceOfTruth Silver badge

    Next in line for a government 'loan'?

    Got to let the plebs pay for it.

    1. Anonymous Coward
      Anonymous Coward

      Re: Next in line for a government 'loan'?

      Silly boy

    2. MachDiamond Silver badge

      Re: Next in line for a government 'loan'?

      "Got to let the plebs pay for it."

      Of course, they are too big to fail.

  3. Anonymous Coward
    Anonymous Coward

    “The incident was isolated and had been contained”

    It’s OK boss.

    Only 430,000 have been impacted!

    Phew.

    1. Rich 2 Silver badge

      Re: “The incident was isolated and had been contained”

      I was just about to point out the same thing.

      The only reason/way this is “contained” is that there is nothing else left to steal!

  4. Anonymous Coward
    Anonymous Coward

    Don't you dare fail to monitor your own supply line then try to wash your hands of it like it was nothing to do with you.

    YOUR supplier

    YOUR sub-contractor

    YOUR problem

    YOUR fault.

    Own it you cowards

    1. Anonymous Coward
      Anonymous Coward

      Also, presumably the upstream supplier has other clients than Harrods. So what else is compromised and where's this responsible disclosure thing we keep hearing about?

  5. MachDiamond Silver badge

    Why the data migration

    If a 3rd party company has access to sensitive data, that should come with company ending risk on both sides. Too bad for Harrods, but they chose to trust the information to somebody else rather than look after it themselves. The question always needs to be asked whether storing certain data is necessary in the first place. Obviously, they think it has value. They should think of it in the same way as a tank farm that stores petrol. There's value there, but also risk that has to be constantly mitigated. If they don't look after it, boom and thanks for playing. Insert more coins to play again.

  6. Taliesinawen Bronze badge

    Blame the Outsourcer and SQL Injection /s

    How would a compromise of a third-party supplier's system give the hackers access to Harrods customers' data.

    “Attackers used exploitation techniques like SQL Injection to gain unauthorized access and attempted extortion.”

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like