Data leak
Harrods Third-Party Vendor Breach
Primary Source βIncident Details
In September 2025, Harrods, the iconic London luxury department store, disclosed that a third-party vendor had been compromised, exposing contact details for online customers. Exposed information included customer names and contact details. Harrods notified affected customers and the ICO. This occurred shortly after the spring 2025 wave of UK retail cyberattacks affecting Marks & Spencer (April 2025), Co-op (April 2025), and others β though Harrods’ incident was attributed to a different vector (third-party vendor compromise rather than direct ransomware attack).
Technical Details
- Initial Attack Vector
- A third-party vendor used by Harrods for customer relationship management was compromised, exposing online customer contact details
Timeline
- 2025-08-01 Breach occurred
- 2025-09-10 Publicly disclosed
- 2025-09-10 Customers notified