Royal Mail, the UK postal service, is investigating a potential data breach, which could expose many gigabits of user data leaked to the dark web.
A user on BreachForum, a dark web forum, claimed on 31 March to have breached Royal Mail, impacting third-party supplier Spectos.
The threat actor, called ‘GHNA’ on the forum, claimed to have stolen 144GB of data, including personal information such as PII addresses, confidential documents, and video meeting recordings.
Other data points could also be affected, including locational data on post office and deliveries, the WordPress database of Royal Mail websites, and mailing lists from Mailchimp.
In a sample shared by the threat actor, 293 folders with 16,549 files were included, containing names, addresses, phone numbers, company information, and even screenshots of meetings between Spectos and Royal Mail.
The threat actor also alleged that this was not the first time German-based Spectos lead to a data leak from the Royal Mail.
Spectos released a statement on April 1 confirming that it had suffered a cyber incident it was investigating, later revealing to Infosecurity  that they could confirm that “unauthorised access” to their systems and personal customer data had happened.
However, the firm said that there were “no indications of an internal attack or the use of leaked access data.”
The firm said that they are taking all the necessary legal and technical steps to mitigate risk, and that their systems are being continually protected and monitored to avoid these incidences.
Royal Mail has said that they are aware of the claim on the dark web and confirmed that Spectos is one of their suppliers.
Recommended
- Royal Mail Suffering ‘Severe Disruption’ Following ‘Cyber Incident’
- Royal Mail Reinstates International Services Following Cyber-attack
- New Royal Mail Drone Trial in Argyll and Bute Launched
Spectos told BleepingComputer that Spectos had been the target of a cyber-attack since 29 March 2024, but that the specific scope of the incident is being investigated.
While Royal Mail and Spectos have yet to reveal more details surrounding the cyber incident, Hudson Rock, a cybersecurity company, has alleged that the hackers gained access to Royal Mail’s systems via employee credentials that were compromised from a Spectos info stealer malware incident back in 2021.
In this case, the infected Spectos employee’s credentials provided a gateway to Royal Mail Group’s systems,” Alon Gal,Hudson Rock CTO, said. “The stolen data sat dormant until recently, when it was weaponized in these high-profile leaks.”
Royal Mail is no stranger to security incidents – the postal service faced a breach back in 2023 in an attack claimed by LockBit.





