Desk live·
ForensicPost
Breaches/Retail/File 25-0929

Attacked in April, Breached in September, Through Somebody Else

Harrods reported that data belonging to around 430,000 customers was taken in a second incident, this one via a third-party supplier. The April attempt and the September breach were not the same event.

Constructed geometry · not a chart of case data
TargetHarrods
ActorUnattributed
D. Kennedy11 min readConfidence: high2 sources reviewed

Harrods reported in late September 2025 that records belonging to approximately 430,000 customers had been taken, and attributed the incident to a third-party supplier. The retailer had been targeted earlier in the year during the April campaign against UK retail.

It Defended Its Own Perimeter And Lost Anyway

The April attempt against Harrods did not produce a comparable disclosure. Whatever the retailer did then — and its own controls appear to have held — the data left five months later through an estate it did not run.

That sequence is the most useful thing in this file. Perimeter defence worked and was insufficient, in the same organisation, in the same year.

On Blaming The Supplier

Naming a supplier as the source is factually accurate and this desk records it as such. It is worth being clear about what it does not do.

The customer’s relationship is with the retailer. The retailer chose the supplier, decided what data to send it, and set the terms. Responsibility for the intrusion sits with the supplier; responsibility for the exposure sits with whoever decided 430,000 customer records should be there. Those are different questions and only the first one gets answered in public.

This is the accountability gap filed at 26-0419 and 26-0403, appearing here in its cleanest form.

How we reported this

Compiled from public reporting, listed below. The supplier was not named in the material we reviewed. We have not established a connection between the April targeting and the September incident, and we do not assert one. Corrections: corrections@forensicpost.com.

Sources
  1. Harrods blames its supplier after crims steal 430k customers’ data in fresh attackThe Register
  2. Why the world’s most prestigious retailers are facing a cybercrime waveBlackFog
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary