Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Data Breach - Harrods Will Not Engage with Its Attackers
Data Breach Attacks Data Protection Latest News News & Analysis

Harrods Will Not Engage with Its Attackers

Kirsten DoyleBy Kirsten DoyleSeptember 30, 20255 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Harrods Will Not Engage with Its Attackers
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Harrods says attackers made contact after a breach compromised data belonging to 430,000 customers. The luxury department store said it will not be engaging with them.   

The information was taken from a third-party provider. In a statement, Harrods said: “We proactively informed affected e-commerce customers on Friday that the impacted personal data is limited to basic personal identifiers including name and contact details, where this information has been provided. It does not include account passwords or payment details. 

“Affected customer records may also have labels related to marketing and services delivered by Harrods. 

“These labels may include tier level or affiliation to a Harrods co-branded card, although this information is unlikely to be interpreted accurately by an unauthorised third party.” 

Harrods said its focus remains on informing and supporting its customers. “We have informed all relevant authorities and will continue to co-operate with them.” 

The attack is understood to affect only a fraction of Harrods shoppers, as most of its sales are made in-store. The company would not reveal the malefactor’s demands or messages. 

The store first disclosed the breach in an email to customers on Friday. It added that the incident was unrelated to attempts earlier this year to penetrate its wider IT systems. 

Cyber-attacks on British firms have mounted in 2025. Co-op this week said an attack that exposed the data of its 6.5 million members had cost £206m in lost sales. M&S reported losses of £300m from similar disruption. Jaguar Land Rover continues to recover from an attack that halted production and forced the government to guarantee a £1.5bn loan to stabilise its supply chain. 

Soft Targets 

Dray Agha, senior manager of security operations at Huntress, said: “Cybercriminals are increasingly targeting third-party suppliers because these vendors often have weaker security defences than the large companies they serve. For a prestigious target like Harrods, breaching a smaller supplier is a far easier backdoor than attacking the company’s main systems directly. This forces organisations to defend not just themselves, but their entire digital ecosystem.” 

A Massive, Widespread Data Security Crisis 

Agha adds that the breach of a single supplier can expose the data of hundreds of thousands of customers across multiple businesses simultaneously. “This incident shows how one vulnerability at a third-party provider can create a massive and widespread data security crisis, amplifying the impact far beyond what a direct attack could achieve. This incident should serve as a stark reminder that a company’s security is only as strong as its least secure vendor. It highlights the urgent need for robust third-party risk management, including continuous security monitoring of partners and clear contractual security requirements, not just one-off checks during onboarding.” 

Connected Through Complex Ecosystems 

Charlotte Wilson, head of enterprise at Check Point Software, added: “We’re seeing a dramatic rise in third-party supply chain attacks, and that’s because so many organisations today are connected through complex ecosystems that hold valuable, integrated data. Check Point has found that 20% of all data breaches in recent years involved a third-party vendor, and breaches tied to third-party access not only took an average of 26 days longer to identify but also cost more; $4.46 million per incident compared to the global average of $4.35 million. 

Third Party Vulnerabilities 

She says the recent incidents mentioned all stem from third-party vulnerabilities. “While payment data wasn’t always exposed, loyalty, marketing and customer records were, and these data sets are extremely valuable to criminals. The first wave of impact is business disruption: downtime, lost sales and reputational harm as organisations scramble to recover. The secondary wave hits consumers: attackers use stolen data to launch convincing phishing texts, scam calls and impersonation websites. For example, a message promising 50% off at a brand you’ve shopped with before can trick customers into handing over credentials, card details, or even installing malware, and they understandably associate that harm with the brand itself, which amplifies reputational damage.” 

AI Makes Follow-on Scams More Dangerous 

According to her, AI is making these follow-on scams more dangerous. “Today, criminals are already using AI, including generative tools, after an initial breach to craft highly tailored, personalised offers that leverage exposed loyalty and marketing data so the scam feels real and pushes victims to impersonation sites. Looking ahead, agentic AI (agents talking to agents without human oversight) risks amplifying this scale and speed even further. 

“Retailers must treat supply-chain risk with the same rigor as their own internal security. That means full visibility of which third-party vendors handle sensitive data, enforcing least-privilege access, network segmentation, and running failure and breach-response tests that include third-party providers. Outsourcing a function does not outsource the risk. Finally, transparency matters. Organisations that are open and proactive after a breach may take an immediate reputational hit, but they also empower customers to protect themselves and reduce the success of follow-on scams, and in doing so, demonstrate real integrity.” 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
  • Kirsten Doyle
    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day
  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

7-Eleven Notifies Franchise Applicants After Breach Exposes Personal Data

May 19, 20262 Mins Read

Canvas cyberattack disrupts universities as ShinyHunters threatens massive data leak

May 12, 20267 Mins Read

Zara Owner Inditex Confirms Customer Data Breach Affecting Nearly 200,000 People

May 11, 20263 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}