Harrods, the renowned London-based luxury retailer, has confirmed a significant data breach affecting 430,000 of its customers after a third-party supplier was compromised by cybercriminals. The company began notifying affected customers on September 26, informing them that their personal data had been accessed during the supplier breach. The stolen data includes basic personal details such as names and contact information, but does not encompass passwords or financial data, according to Harrods' official statements. Some records also contained marketing-related information, including Harrods membership tier levels and affiliations with co-branded cards, though the retailer believes this information would be difficult for unauthorized parties to interpret accurately. Harrods emphasized that its own internal systems were not targeted or compromised in the incident, and the breach was isolated to the unnamed third-party provider. The company has received direct communications from the threat actor responsible for the breach but has stated it will not engage with them. Harrods has reported the incident to all relevant authorities and is cooperating fully with ongoing investigations. The retailer has also reassured customers that the incident is unrelated to a previous cyberattack earlier in the year, which was attributed to the Scattered Spider group. In that earlier event, Harrods successfully blocked the attackers from accessing its systems, while other retailers such as Marks and Spencer and Co-op were also targeted. The current breach was first reported by UK media outlets after Harrods began customer notifications. The company operates a comprehensive e-commerce platform serving international customers, making the exposure of customer data particularly concerning. Harrods has not disclosed the identity of the compromised supplier, citing ongoing investigations and containment efforts. The company’s focus remains on supporting affected customers and maintaining transparency throughout the incident response process. No evidence has been presented to suggest that the compromised data has been used for fraudulent purposes at this time. Harrods has reiterated its commitment to data security and is reviewing its relationships with third-party suppliers to prevent similar incidents in the future. The breach highlights the ongoing risks associated with supply chain security in the retail sector. Customers have been advised to remain vigilant for potential phishing attempts or scams leveraging their exposed information. The incident underscores the importance of robust third-party risk management and timely communication with affected stakeholders.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Harrods publicly confirmed the new incident in late September 2025, saying the breach stemmed from a third-party provider and was isolated and contained. The company said it had notified affected customers and relevant authorities and warned customers to watch for phishing and social engineering.
After the supplier-linked breach, the threat actor contacted Harrods directly, which the company said was likely an extortion attempt. Harrods stated it would not engage with the attackers.
In a separate 2025 incident, attackers compromised an external supplier connected to Harrods' e-commerce operations and stole about 430,000 customer records. The exposed data included names and contact details, and for some customers internal marketing or service labels, but not passwords, payment data, or order histories.
In May 2025, Harrods said it stopped an attempted intrusion and restricted internet access across its sites as a defensive measure. The incident was later described as separate from the later customer-data breach and attributed to Scattered Spider.
10 references tracked. Mallory keeps watching after this page renders.
blog.usecure.io
Open sourcecomputing.co.uk
Open sourcescworld.com
Open sourcecyberpress.org
Open sourcehackread.com
Open sourceinfosecurity-magazine.com
Open sourcebleepingcomputer.com
Open sourcebbc.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.