Flink, Hackers

Flink Hackers Turn to Customers After Grocery Delivery Firm Refuses to Pay Up

Published on 09/29/2026 at 05:30 | Editorial boerse-global.de

Attackers behind the Flink breach are emailing stolen-data victims directly after the firm refused to pay, demanding about €11.50 each.

Flink Data Breach Turns Into Extortion of Customers and Staff
Flink Hackers Turn to Customers After Grocery Delivery Firm Refuses to Pay Up Illustration mit AI erstellt.

A cyberattack on the grocery delivery service Flink has escalated into a direct shakedown of the people whose data was stolen, after the company declined to meet the attackers' initial ransom demands.

Intruders reached an internal ordering system — the so-called Order Hub at one of Flink's local delivery depots — and walked away with a large volume of personal master data, according to reports on the breach. Flink has confirmed the incident.

What was taken, and what wasn't

Names, delivery addresses, email addresses and phone numbers are among the compromised records, which cover both customers and staff. In some instances, specific delivery instructions and details of past orders were also caught up in the leak.

Flink stressed in a statement that sensitive financial information was explicitly not part of the haul. Passwords, payment details, bank account information and credit card data remain secure based on what is currently known, the company said.

Just how far the breach reaches is still being worked out. At least 10,000 customers are said to be affected in the Netherlands, while no precise figure has yet emerged for the German market. Unconfirmed reports suggest the full trove could hold data on roughly one million customers along with 13,000 employees — numbers Flink has so far declined to officially confirm.

From corporate target to individual inboxes

When the delivery firm refused to make an initial ransom payment, the attackers switched tactics. Operating under the name "LPG Group" — a label that has not yet been independently verified — they went straight to the affected individuals. Customers and employees began receiving extortion emails sent from a Flink-like address, each one greeting the recipient by their correct name.

The technique on display is known as "triple extortion." Having first demanded payment from Flink in the cryptocurrency Ethereum, and having been met with silence at the negotiating table, the criminals are now asking customers to foot the bill. Some users were told to pay 0.005 Ether, the equivalent of about €11.50.

Collectively, the perpetrators are aiming to gather 100 ETH — roughly €230,000. In exchange, they promise to delete the data; if the money does not materialise, they threaten to sell the information on the darknet. Flink is urging people in the strongest terms not to respond to the demands or hand over any money.

How they got in

Investigators currently believe the point of entry was a compromised account belonging to a former employee. Flink moved quickly once the security gap came to light, shutting down the access in question and launching a full investigation.

Outside IT forensics specialists and cybersecurity experts have been brought in to assist. According to the company, there is presently no indication that any further unauthorised access has occurred.

Flink has already notified the relevant data protection authorities and informed affected customers about the breach. Those caught up in the incident may have grounds for legal claims — and lawyers are pointing to the General Data Protection Regulation (GDPR) as the basis.

A ruling by Germany's Federal Court of Justice (Bundesgerichtshof) at the end of 2024 held that losing control over personal data can in itself constitute a compensable non-material harm under Article 82 of the GDPR, which could open the door to damages claims from those affected.

Disclaimer...

en | boerse | 70196005 |