Skroutz Last Mile, the courier company of the Skroutz group, announced on Tuesday, September 23, 2026, that it had detected unauthorized access to one of its information systems, which contained parcel shipment data. According to the announcement, the exposed data included names, addresses and contact numbers of recipients. The company assures that no credit card details, payment data or user credentials were affected, as these are not stored in its own systems.
The case was initially revealed through a report in Apogevmatini, which reproduced the company's information. Skroutz Last Mile states that it took immediate action, took appropriate security measures and is acting in cooperation with the competent supervisory authorities — apparently the Personal Data Protection Authority (PDPA), as provided for in Article 33 of the GDPR. No information has been provided, so far, on the number of customers affected or on the manner in which access was obtained.
See also our recent coverage of the massive McKesson breach, which showed how easily stolen customer data can be used as a blackmail or phishing tool.

What exactly did Skroutz Last Mile say?
The company's official announcement is relatively laconic. It confirms that specific categories of personal data related to parcel shipments were affected and explicitly delimits what was not affected. At the same time, it urges customers to be extra careful with suspicious emails, SMS and messages that appear to come from Skroutz Last Mile but do not come from its official channels.
- Affected data: recipients' names, delivery addresses, contact numbers.
- Data not affected: credit cards, payment data, passwords, and account credentials.
- Company actions: immediate response, notification of competent supervisory authorities, implementation of additional security measures.
- Recommendation to customers: beware of phishing emails and SMS, as well as telephone attempts requesting personal information or passwords.
What the announcement doesn't say is perhaps equally important. The company hasn't specified when exactly the incident was discovered, how long the data was accessible by an unauthorized third party, whether the records were actually exfiltrated or if they were detected before it was completed, and how many recipients were affected.
How the incident could have happened — technical scenarios
The SecNews technical team notes that in last-mile logistics companies, where each package is associated with a set of personal information, breaches tend to follow specific, known patterns. Without official technical details from Skroutz Last Mile, the possible scenarios that fit the description “unauthorized access to a shipping system” are as follows:
- Package Tracking API Vulnerability: Tracking systems often expose endpoints that accept a tracking number as a parameter. If the endpoint does not properly check the caller's permissions, it could allow a third party to read data from another recipient — a classic Insecure Direct Object Reference (IDOR).
- Hacked partner eshop: hundreds of Greek eshops connect via API to Skroutz Last Mile to create and track shipments. If one of these partners is hacked and its API keys are stolen, the attacker can extract shipment data without hitting Skroutz Last Mile itself.
- Employee account compromised: employee or partner credentials may have been exposed to phishing or a previous leak, without MFA blocking entry, giving access to the internal package management dashboard.
- Internal online panel report: an admin or reporting panel that was uploaded as an internal tool, but left publicly accessible without access control — a very common scenario in fast-growing logistics companies.
- Supply chain attack: breach of an external SaaS provider (analytics, CRM, call center) that has read-only access to recipient data.
The fact that the company emphasizes that no credentials were affected is a strong technical indicator: this is likely not a breach of Skroutz's central user base, but a more limited system or endpoint that serves only the flow of shipments. This is more consistent with an IDOR/API abuse scenario or a compromised partner system, rather than a full-scale ransomware attack on the company's central systems.

Similar violations in courier companies abroad
Last-mile companies have become some of the most attractive targets for cybercriminals in recent years, precisely because they collect huge volumes of contact information. See also the Florida DMV breach by ShinyHunters, where similar data was stolen and then used in targeted phishing campaigns.
- OnTrac (USA, July 2026): a courier company that reported that malicious visitors had breached its corporate network and may have gained access to personal customer information.
- ShipMonk (Trezor shipping provider, 2026): A breach at a shipping provider led to the exposure of names, addresses, phone numbers, and order numbers of 67,000 Trezor customers in the US. A typical supply chain attack scenario.
- CenterPoint (US, September 2026): utility company that saw 7.49 million customer records exposed with full address and phone details.
The common pattern in all these cases is that the stolen data, even when it doesn’t include cards or passwords, directly feeds smishing and voice phishing. The attacker knows real names, real addresses, and when someone is expecting a package — and uses this information to convince the victim to pay “delivery fees,” download a malicious app, or give out e-banking passwords.

What customers should do immediately
Even when no passwords or cards have been leaked, the leak of a name, address, and phone number is enough to set up very convincing phishing campaigns. The SecNews editorial team recommends to customers who have used Skroutz Last Mile in recent months:
- Ignore SMS with a link for "delivery fees": Skroutz Last Mile does not ask for an additional fee via a link in an SMS. Any such message is almost certainly smishing.
- Always confirm the parcel status from the app: not from a link in an email or SMS, but by directly opening the official Skroutz app or page.
- Enable 2FA on your Skroutz account: although passwords are not listed as affected, the identity of an account always deserves extra protection.
- Monitor bank transactions: card details were not leaked, but a convincing phishing attacker may ask for them “for confirmation.” If you took such a step after a suspicious message, notify your bank immediately.
- Report suspicious SMS/emails: forward them to Skroutz Last Mile and the Cybercrime Prosecution Service, so that the pattern of attacks can be recorded.
- Exercise your rights under GDPR: request information from Skroutz's Data Protection Officer (dpo@skroutz.gr) if your data was in the affected set.

Frequently asked questions
Should I change my Skroutz password? According to the company, passwords were not affected. However, if it's been a while since you changed your password or you use it on other services, it's always a good time to refresh and enable two-factor authentication.
Is my money at risk? Credit card and payment details are not stored on Skroutz Last Mile's systems and, according to the announcement, were not affected. The biggest risk is indirect: someone attempting to scam you via phishing SMS or email that will list correct names and addresses.
Has the Data Protection Authority been informed? The company states that it is acting "in cooperation with the competent supervisory authorities", which in practice means notification to the Data Protection Authority within 72 hours as provided for in Article 33 of the GDPR. An official announcement from the Authority has not yet been published.
The Skroutz Last Mile case shows, once again, that in the modern supply chain, the most sensitive resource is not the package itself, but the personal information that accompanies it. The SecNews technical team will monitor the development of the incident and will publish updates as soon as more technical information or an official position from the ADA becomes available.
