Harrods reported in late September 2025 that records belonging to approximately 430,000 customers had been taken, and attributed the incident to a third-party supplier. The retailer had been targeted earlier in the year during the April campaign against UK retail.
It Defended Its Own Perimeter And Lost Anyway
The April attempt against Harrods did not produce a comparable disclosure. Whatever the retailer did then — and its own controls appear to have held — the data left five months later through an estate it did not run.
That sequence is the most useful thing in this file. Perimeter defence worked and was insufficient, in the same organisation, in the same year.
On Blaming The Supplier
Naming a supplier as the source is factually accurate and this desk records it as such. It is worth being clear about what it does not do.
The customer’s relationship is with the retailer. The retailer chose the supplier, decided what data to send it, and set the terms. Responsibility for the intrusion sits with the supplier; responsibility for the exposure sits with whoever decided 430,000 customer records should be there. Those are different questions and only the first one gets answered in public.
Compiled from public reporting, listed below. The supplier was not named in the material we reviewed. We have not established a connection between the April targeting and the September incident, and we do not assert one. Corrections: corrections@forensicpost.com.