Site navigation

Customer Data Compromised in Harrods Data Breach

Elizabeth Greenberg

,

harrods data breach
The current breach is unrelated to the cyber-attacks that rocked UK retail earlier in the year.

Harrods, the luxury department store based in London, has revealed that some of its online customers have had their personal information compromised via a third-party breach.

The threat actor had been in contact with the store, Harrods said over the weekend, saying it had refused to engage with the alleged attacker.

“We proactively informed affected e-commerce customers on Friday that the impacted personal data is limited to basic personal identifiers including name and contact details, where this information has been provided. It does not include account passwords or payment details,” the firm said.

“It is important to note that the information was taken from a third-party provider and is unconnected to attempts to gain unauthorized access to some Harrods systems earlier this year.”

This indicates that the current breach is not directly resulting from the breach that rocked UK retail – including Harrod’s – this May. Notorious ransomware gang Scattered Spider targeted major retailers, including M&S and Co-op, bringing many stores’ operations to a stand still and disruption to their online platforms for weeks.

The attacks resulted in a near £300m loss for M&S, and an around £206m loss for Co-Op. Harrods appeared to be less affected by the breach overall, though it did face disruptions.

The current breach reportedly impacted up to 430,000 customer records, which includes personal information but not payment information, the firm stressed.


Recommended reading


“Our focus remains on informing and supporting our customers. We have informed all relevant authorities and will continue to co-operate with them,” a spokesperson for the company said in a statement.

Names, contact details, and information relating to loyalty cards, marketing preferences, and relations to other companies were compromised in the breach.

Harrods told customers that “this information is unlikely to be interpreted accurately by an unauthorised third party.”

The company as reiterated “that no payment details or order history information has been accessed and the impacted personal data remains limited to basic personal identifiers as advices previously.”

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data