Luxury British department store Harrods has warned some customers of a data breach, after personal details may have been stolen from online systems.

The company announced late Friday that some of names and contact information its online customers' were stolen after a breach at a third-party provider. "We have informed affected customers that the personal data is limited to basic personal identifiers, such as name and contact information, but does not include account passwords or payment information," it said in a statement.
He added that the incident was "isolated" and has been contained, without providing further details.
Harrods clarified that the data breach was not related to the May incident, when it had restricted internet access to all its websites as a precautionary measure after an attempted unauthorized access to its systems.
See also: Acoustic Side-Channel Attacks: The Invisible Gateway to Data Leakage
Four people were arrested in July on suspicion of involvement in cyberattacks against Harrods and two other leading British retailers, Marks & Spencer and Co-op. The suspects were released on bail pending further investigations.
Many cyberattacks targeting British businesses
Several other cyberattacks have targeted high-profile British businesses in recent months. Last week, Jaguar Land Rover, Britain's largest carmaker, said its production lines would remain closed until at least October 1, following a cyberattack in August.
On Friday, the BBC and other British media reported that hackers stole information on thousands of children from the Kido in London and posted some of the children's photos and details on the dark web.

The Metropolitan Police also said that investigations into “a ransomware attack on a London-based organization” are ongoing and no arrests have been made.
Do the attacks on Harrods and other businesses show this?
The recent data breach at Harrods is the latest in a string of incidents that underscore the vulnerability retail industry ’s growing to cyberattacks. While the data exposed is considered to be of limited value—names and contact details—the incident itself highlights how fragile the security ecosystem can be when it relies on third-party providers . Outsourcing technology services, while common practice, creates new levels of risk, as each link in the chain can be a potential entry point for malicious actors.
See also: Salt Typhoon attacks telecommunications infrastructure
Retail has been a target for hackers for years, not only because of the vast amount of personal and financial data it handles, but also because of the pressure companies face to maintain a seamless customer experience. Even a outagecan result in lost revenue and damaged reputations. As a result, attackers often use the threat of data breaches or the paralysis of critical systems as leverage for extortion, with ransomware now the most common form of attack.
The Harrods example demonstrates that even luxury brand names, which are built on a sense of trust and security, are not exempt from cybercriminal activity. On the contrary, they are high-value targets, as the theft of even basic personal information can pave the way for phishing attacks, identity theft or more sophisticated social engineering campaigns.

Protection
In such a landscape, retailers are called upon to operate on three levels: prevention, detection and incident management. Prevention means strong security policies, multi-factor authentication (MFA), frequent penetration testing and rigorous partner evaluation. Detection requires sophisticated network monitoring tools and the use of artificial intelligence to identify suspicious activity in real time. Finally, incident management is equally crucial: the speed and transparency with which a company responds to breaches can limit the impact and strengthen public trust in the long term.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: New Phishing Attack Targets PyPI Administrators
The picture emerging in the United Kingdom, with attacks against iconic retail chains as well as sensitive organizations such as daycare centers, shows that cybercriminals do not act randomly: they follow the logic of "maximum efficiency", targeting either large brands with international visibility or vulnerable organizations with valuable data.
Overall, the Harrods case is a reminder that cybersecurity in retail is no longer a technical detail that concerns only the IT department. It is a strategic matter of corporate survival. Businesses that invest in resilient and multi-layered security systems will be the ones that will maintain their consumers’ trust in the future.
