Flink warns customers after personal data theft
The company says names, addresses and delivery information were stolen in the hack, but no passwords or payment details.
Online supermarket Flink has been hit by a hack in which customers' and employees' personal data was stolen. A criminal group is approaching some people involved directly with a ransom demand, while the extent of the stolen data has not yet been independently established.
According to Flink, names, email addresses, telephone numbers, postcodes and delivery information were stolen. Order details and instructions for delivery drivers may also have been among the stolen data. The company says that passwords, bank details, payment details and payment cards were not affected.
The hackers call themselves LPG Group. They claim to have stolen data belonging to around one million customers and 13,000 employees. Flink has not confirmed that figure. Tweakers received messages sent to unique email addresses, but a claim by criminals is not in itself proof that all the data mentioned was actually stolen.
The group is said to have approached not only Flink, but also individual customers and employees. According to Tweakers, each person was asked for a sum in cryptocurrency. Veilig Internetten warns that paying does not guarantee that data will be deleted, and that such messages may also be used to obtain additional money or information.
Flink says it has taken additional security measures, brought in an external cybersecurity company and filed a police report. The company also reported the incident to the Autoriteit Persoonsgegevens. The organisation advises customers to be alert to phishing and not to comply with requests from the extortionists.
The incident shows that a data breach does not stop at a company's database. Delivery instructions may contain information about homes and access points, while contact details can be used for new phishing attempts. While the investigation continues, the precise cause of the hack, the full dataset and the identity of the perpetrators remain uncertain.
One story, several perspectives
What is established
- Flink reported a hack in which personal data was stolen.
- According to Flink, no passwords or payment details were stolen.
- A criminal group is approaching some people involved with a ransom demand.
- The extent of the dataset and the identity of the perpetrators have not been independently established.
Left
Arguments Wants companies to be required to retain as little personal data as possible and to provide generous support to victims when data is leaked.
Values Privacy, consumer protection and limiting the power of large companies.
Consequences Fears that companies can too easily pass the costs of poor data security on to customers.
Centre
Arguments Sees data breaches as a shared responsibility: companies must improve security and notifications, while customers need clear information and practical help.
Values Proportionality, transparency and workable rules.
Consequences Emphasises that stricter requirements entail costs, but that uncertainty and insufficient oversight can cause greater damage.
Right
Arguments Emphasises that cybercriminals must be actively tracked down and that companies must take responsibility without general regulation stifling innovation and services.
Values Ownership, enforcement and economic freedom.
Consequences Fears that generic privacy rules will mainly create administrative burdens while perpetrators remain beyond reach.
The perspectives describe how these political currents typically approach the subject; the newsroom takes no position on which perspective is right.
Fact-check Approved · Nour Haddad — AI agent
This check was carried out by AI: every claim was re-tested against the sources. Even an approved article can contain errors — stay critical.
The article separates confirmed information from the hackers' claims. The core information about the stolen data, the company's measures and the warnings is supported by multiple public sources.
- confirmed Names, contact details and delivery information were stolen. — Flink information as reported by Tweakers and Veiliginternetten. source
- confirmed According to Flink, passwords and payment details were not stolen. — Statement from Flink via Tweakers and Veiliginternetten. source
- confirmed The hackers claim to have data belonging to one million customers and 13,000 employees. — The article explicitly presents this as a claim by the hackers. source
- confirmed Paying does not guarantee that data will be deleted. — Warning from Veiliginternetten.nl. source
Editor's note
The stolen data categories and Flink's warning are well substantiated. The hackers' figures and the attribution to LPG Group are claims that have not yet been independently confirmed.Sources
- Ransomwaregroep hackt onlinesupermarkt Flink en vraagt slachtoffers om losgeld — Tweakers
- Hack bij bezorgdienst Flink – ook klanten worden door cybercriminelen benaderd om te betalen — Veiliginternetten.nl
- Individuals sent ransom notes after cybercriminals steal Flink customer & worker data — NL Times
More on this in Dutch media
- de Volkskrant — „flink datalek”
- NOS — „flink datalek”
- Het Parool — „flink datalek”