HomeSecurityHarrods: Data breach exposes 430,000 customer records

Harrods: Data breach exposes 430,000 customer records

Luxury department store Harrods has revealed a major data breach affecting around 430,000 customer records, following a breach by a third-party provider.

Harrods Data Breach

The hackers behind the attack have contacted the store, but Harrods has stated that it will not cooperate with the threat actor (suggesting that there was likely a ransom demand).

The breach, which Harrods announced to affected customers via email on Friday, September 26, 2025, stemmed from a security failure at an unnamed external supplier and not Harrods' internal systems.

See also: RedNovember breached critical infrastructure worldwide

Harrods – Data Breach: What Data Has Been Exposed?

The company has stressed that the data breached is limited to basic personal identifiers and does not include highly sensitive information. The stolen data mainly includes names and contact details provided by customers. In some cases, information about marketing preferences, loyalty program status and links to Harrods co-branded credit cards was also exposed. However, a company spokesperson noted that this marketing-related data is “unlikely to be misinterpreted by an unauthorized third party.”

Harrods has reassured customers that no financial information , such as payment details or account passwords , was accessed . The breach is thought to have affected a small percentage of the store's overall clientele , as the majority of Harrods customers shop in-store rather than online.

Harrods: Data breach exposes 430,000 customer records

In response to the incident, Harrods has proactively informed affected customers and notified all relevant authorities, including the Information Commissioner's Office (ICO), in accordance with the UK's GDPR regulations

A spokesperson said: “Our focus remains on informing and supporting our customers. We have informed all relevant authorities and will continue to work with them.”

See also: Hackers use Facebook and Google ads to steal data

This security incident is separate from a previous attempted cyberattack on Harrods’ internal systems in May 2025. That incident, part of a wider series of attacks on UK retailers such as M&S and Co-op, led Harrods to restrict internet access as a precaution, but did not result in a data breach. The recent breach highlights a growing trend of cybercriminals targeting partners supply chain to access large companies’ data. Harrods online customers are being urged to be vigilant against potential phishing and social engineering attempts.

Aiming for the supply chain

The Harrods data breach case once again opens up the debate about the vulnerable nature of the supply chain in the digital age. The fact that the attack did not take place directly on Harrods’ internal systems, but via a third-party provider, clearly shows how cybercriminals are shifting their focus from the powerful “castles” of large organizations to the less protected gateways connected to them.

Harrods: Data breach exposes 430,000 customer records

It’s a pattern we’re seeing more and more often: companies that invest millions in strengthening their own security are still exposed, as the security chain is only as strong as its weakest link. For luxury retailers like Harrods, the challenge is twofold. On the one hand, they have to protect data on hundreds of thousands of high-net-worth customers – particularly attractive targets for malicious attacks. On the other, they have to ensure that their partners, from CRM providers to marketing agencies, adhere to equally stringent cybersecurity standards.

See also: Security flaws in Tile allow location tracking

The new breach also highlights the risk of secondary attacks. Even if no payment details have been leaked, data linked to loyalty cards and marketing preferences can be used in personalized phishing campaigns. In practice, customers can become targets for well-crafted scams that mimic Harrods’ communication style.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The case reminds us that the issue is not just technical, but also one of trust. In the world of luxury retail, where the relationship with the customer is based on a sense of security and exclusivity, a data breach not only affects privacy, but also the very identity of the brand.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS