Data Breach

New Harrods Data Breach Exposes 430,000 Customer Personal Records

Luxury department store Harrods has disclosed a significant data breach affecting approximately 430,000 customer records after a third-party provider was compromised.

The hackers behind the attack have contacted the retailer, but Harrods has stated it will not engage with the threat actor, suggesting a potential ransom demand was made.

The breach, which Harrods first communicated to affected customers via email on Friday, September 26, 2025, originated from a security failure at an unnamed external supplier, not from Harrods’ internal systems.

The company has emphasized that the compromised data is limited to basic personal identifiers and does not include highly sensitive information.

Harrods Data Breach

The stolen data primarily includes names and contact details that customers had provided. In some cases, information related to marketing preferences, loyalty program status, and affiliations with Harrods’ co-branded credit cards was also exposed.

However, a company spokesperson noted that this marketing-related data is “unlikely to be interpreted accurately by an unauthorised third party”.

Harrods has reassured its customers that no financial information, such as payment card details or account passwords, was accessed during the incident. The breach is understood to have affected a small proportion of the store’s total clientele, as the majority of Harrods customers shop in-store rather than online.

In response to the incident, Harrods has proactively informed affected e-commerce customers and notified all relevant authorities, including the Information Commissioner’s Office (ICO), in compliance with UK GDPR regulations.

A spokesperson stated, “Our focus remains on informing and supporting our customers. We have informed all relevant authorities and will continue to co-operate with them”.

This security event is separate from a previous cyberattack attempt on Harrods’ internal systems in May 2025. That earlier incident, part of a wider series of attacks on UK retailers like M&S and Co-op, prompted Harrods to restrict internet access as a precaution but did not result in a data compromise at the time.

The recent breach highlights a growing trend of cybercriminals targeting supply chain partners as a weaker link to access data from major corporations. Customers of Harrod’s online store are advised to be vigilant against potential phishing and social engineering attempts.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Hackers Trick Users to Download Weaponized Microsoft Teams to Gain Remote Access

A sophisticated cyber campaign is exploiting the trust users place in popular collaboration software, tricking…

5 hours ago

New Spear-Phishing Attack Delivers DarkCloud Malware to Steal Keystrokes, FTP Credentials and Others

A newly observed spear-phishing campaign is leveraging sophisticated social engineering lures to distribute DarkCloud, a…

8 hours ago

SVG Security Analysis Toolkit to Detect Malicious Scripts Hidden in SVG Files

As attackers increasingly leverage Scalable Vector Graphics (SVG) for stealthy code injection, security researchers face…

8 hours ago

New TamperedChef Malware Leverages Productivity Tools to Gain Access and Exfiltrate Sensitive Data

A sophisticated malware campaign has emerged that weaponizes seemingly legitimate productivity tools to infiltrate systems…

8 hours ago

JLR Confirms Phased Restart of Operations Following Cyber Attack

Jaguar Land Rover (JLR) has confirmed it will begin a phased restart of its manufacturing…

9 hours ago

New Malware-as-a-Service Olymp Loader Promises Defender-Bypass With Automatic Certificate Signing

The cybersecurity community is currently observing a surge in interest around Olymp Loader, a recently…

9 hours ago