Index live· 1,284 files · 148 editions
ForensicPost

Search the index

48 results
Try
Results for “Retail”Newest first
26-0807b
File

Levi Strauss Says Social Engineering Compromised Three Employee Computers

Three compromised laptops, corporate data taken, and a filing that answers the shareholder question only.

UnattributedSocial engineeringRetailVerification
Sev 2TargetLevi Strauss & Co.ActorUnattributedUSA
26-0730
File

An Energy Retailer, and the Customers Who Cannot Switch Quickly

Customer data leaked at a retailer serving 4.8 million. That figure is the customer base, not the affected count — and the distinction keeps getting lost.

UnattributedUnder reviewPublic sectorUtilities
Sev 3TargetOrigin EnergyActorUnattributedAustralia
26-0725
File

Four Arrested Over UK Retail Attacks Linked to Scattered Spider

Four arrested over attacks assessed in the hundreds of millions. Three were teenagers, and the technique was a phone call.

Scattered SpiderEnforcement actionRetailEnforcement
Sev 3TargetUK retail sectorActorScattered SpiderUnited Kingdom
26-0723
File

RevolutionParts Breach Exposed More Than Five Million Records

Five million records from a platform none of the customers knew they were using. Correlated failure, uncorrelated disclosure.

UnattributedUnder reviewRetailThird party
Sev 3TargetRevolutionPartsActorUnattributed
26-0702
File

Qantas Customer Data Published a Year After Third-Party Platform Breach

Up to six million customers exposed in 2025; records published in 2026. Notification law assumes an incident that ends.

Scattered Lapsus$ HuntersThird-party platformRetailAviation
Sev 4TargetQantasActorScattered Lapsus$ Hunters
26-0620
File

Estee Lauder Reports Oracle E-Business Suite Breach Undetected for Ten Months

An Oracle E-Business Suite flaw exploited in August 2025, found in June 2026. The records were employees’: identity documents, bank details, health data.

UnattributedOracle EBS flawRetailDetection
Sev 3TargetEstée LauderActorUnattributed
26-0608
File

Nobody Breached Anything; They Just Logged In

Valid credentials from somebody else’s breach, accepted. Nothing failed in the conventional sense, and customer data went anyway.

UnattributedCredential stuffingRetailIdentity
Sev 3TargetChick-fil-AActorUnattributed
26-0527
File

Carnival Reports Phishing Breach Affecting Close to Six Million Guests

A phishing-led compromise affecting close to six million guests, including passport numbers a passenger could never have declined to provide.

UnattributedPhishing → accountRetailIdentity
Sev 4TargetCarnival CorporationActorUnattributed
26-0515
File

Breached in 2024, Found in 2025, Disclosed in 2026

Two years between the intrusion and the notification, on identity documents. Small organisations produce long intervals, and mostly go unrecorded.

UnattributedRetailDetection
Sev 3TargetVacation Myrtle BeachActorUnattributed
26-0425
File

Ten Million Claimed, Five and a Half Million Verified

Ten million claimed, 5.5 million verified. A leak-site figure is an advertisement written by the seller.

ShinyHuntersUnder reviewRetailVerification
Sev 3TargetADTActorShinyHunters
26-0424
File

Luxury Houses Share a Customer List and a Platform

Separate houses, one platform. A luxury purchase history is a map of where valuable objects live.

ShinyHuntersSocial engineering → CRMRetailRetail
Sev 3TargetAdidas, Pandora, LVMH housesActorShinyHunters
26-0423
File

Six Hundred Thousand Claimed, 185,000 Stood Up

600,000 claimed, 185,300 verified — and a franchise structure where the brand, the data holder and the notifier are three parties.

ShinyHuntersSalesforce misconfigurationRetailVerification
Sev 3Target7-ElevenActorShinyHunters
26-0415
File

UK Retail Attacks Classified as a Category 2 Systemic Event

A hurricane-style category applied to a cyber event. Severity is a property of the victim and its coupling, not of the attack.

UnattributedMethodologyMultipleMethod
Sev 3TargetIncident severity classificationActorUnattributedUnited Kingdom
26-0411
File

M&S and Co-op Intrusions Assessed as a Single Event Costing up to £440 Million

A phone call to an outsourced service desk, a password reset, and £270–440 million across two retailers assessed as one event.

Scattered SpiderHelp-desk social engineeringRetailRetail
Sev 5TargetMarks & Spencer and Co-opActorScattered Spider
26-0213
File

Japanese Hotel Chain Ransomware Hit Business Systems but Not Membership Server

Business systems encrypted; the segmented membership server untouched. Our database is mostly a record of controls that failed.

UnattributedRansomwareRetailHospitality
Sev 2TargetWashington Hotel chain (JP)ActorUnattributedJapan
26-0204
File

Harrods Targeted in the Same Scattered Spider Wave as M&S and Co-op

Three retailers, one crew, one window. The reusable asset is the shared supplier estate behind the brands.

Scattered SpiderNot disclosedRetailRetail
Sev 3TargetHarrodsActorScattered Spider
26-0202
File

Panera Bread Breach Exposed 5.1 Million Loyalty Accounts

5.1 million loyalty accounts. Nothing sensitive by field name; a good deal sensitive by implication.

ShinyHuntersSystem compromiseRetailRetail
Sev 2TargetPanera BreadActorShinyHunters
26-0201
File

Chanel Named Among Organisations Hit in Third-Party Data Campaign

Another luxury house through another third-party platform. Discretion is part of what the customer is buying.

UnattributedThird-party platformRetailRetail
Sev 3TargetChanelActorUnattributed
26-0122
File

Canada Computers Guest Checkout Captured Payment Card Data for a Month

Cards captured in flight through guest checkout. Storing nothing protects the database and not the customer.

UnattributedPayment page compromiseRetailRetail
Sev 3TargetCanada ComputersActorUnattributed
25-1130
File

Coupang Breach Affected 33.7 Million Customer Accounts

Where a market has one dominant platform, the distinction between a customer list and a national register largely disappears.

UnattributedRetailRetail
Sev 4TargetCoupangActorUnattributed
25-1001
File

Three Hundred and Forty-Three Gigabytes, Claimed in November

What was counted is not what matters, and what matters was not counted.

EverestRetailVerification
Sev 3TargetUnder ArmourActorEverestUSA
25-1022
File

Retail, Insurance, Aviation and Universities All Fell to the Same Phone Call

There is no packet to inspect and no domain to block. The output of the call is a legitimate action by an authorised person.

MultipleVoice phishingMultipleMethod
Sev 5TargetMultiple sectorsActorMultiple
25-1002
File

A Retailer That Was Never Attacked Stopped Selling

No data involved, no system touched, no notification anywhere. The company simply could not trade.

RansomHouseSupplier incidentRetailRetail
Sev 3TargetMujiActorRansomHouseJapan
25-0929
File

Attacked in April, Breached in September, Through Somebody Else

Its own controls held in April. The data left in September through an estate it did not run.

UnattributedSupplier compromiseRetailRetail
Sev 3TargetHarrodsActorUnattributed
25-0808
File

Retail Recorded 837 Incidents and 419 Confirmed Breaches in a Quarter

837 incidents, 419 confirmed breaches. The 418 that never became a disclosure are the sector’s real attack volume.

MultipleVariousRetailAnalysis
Sev 3TargetRetail sectorActorMultiple
25-0724
File

Four Arrested Over M&S, Co-op and Harrods Intrusions

An unsophisticated technique that works is not a lesser threat than a sophisticated one. It is a worse one.

Scattered SpiderSocial engineeringRetailEnforcement
Sev 3TargetUK retail campaignActorScattered SpiderUnited Kingdom
25-0710
File

Three LVMH Brands Disclosed Separate Breaches Between May and July

Three brands, three jurisdictions, three timetables. The pattern exists only above the level anyone is obliged to report.

UnattributedRetailRetail
Sev 3TargetLVMH brandsActorUnattributed
25-0616
File

The Most Expensive Sector to Be Breached In

A retailer and a bank suffering identical intrusions produce very different invoices, and the difference is regulation rather than damage.

MultipleVariousFinanceAnalysis
Sev 3TargetFinancial sectorActorMultiple
25-0615
File

Ahold Delhaize USA Targeted as Parent of Giant and Food Lion

A notification arriving from an entity the recipient may not recognise as connected to the shop.

Scattered SpiderRetailRetail
Sev 3TargetAhold Delhaize USAActorScattered Spider
25-0603
File

Names, Emails and Countries of Residence — Which Is the Whole Problem

Limited fields, no financial data, low risk — the standard reassurance. It does not hold when being on the list is the sensitive fact.

UnattributedRetailRetail
Sev 2TargetCartierActorUnattributed
25-0526
File

Victoria's Secret Shut Corporate Systems and Postponed Its Earnings Release

A three-day e-commerce shutdown was a decision, not a failure. The delayed earnings release is the mandatory signal breach law never produces.

UnattributedRetailRetail
Sev 3TargetVictoria’s SecretActorUnattributedUSA
25-0512
File

Scattered Spider Worked UK Retail From April, Then Moved to US Retail

A group that works one industry at a time is reusing research, not expressing a preference. That makes the next target legible.

Scattered SpiderSocial engineeringRetailActors
Sev 4TargetRetail sectorActorScattered Spider
25-0501
File

Co-op Confirms Data of All 6.5 Million Members Was Taken

Notifications usually describe a subset. Co-op did not have that sentence available — a loyalty scheme is built to be complete.

Scattered SpiderSocial engineeringRetailRetail
Sev 4TargetCo-operative GroupActorScattered SpiderUnited Kingdom
25-0430
File

Co-op Put Its Revenue Loss From the April Intrusion at £206 Million

£206 million in revenue that never arrived. Groceries are perishable and demand is not deferred — the loss is permanent in a way a car maker’s is not.

Scattered SpiderHelp-desk social engineeringRetailRetail
Sev 4TargetCo-opActorScattered Spider
24-1205
File

Termite Claims Blue Yonder Data and Says It Will Reuse the Email Lists

A stated plan costs nothing to announce and cannot be checked, and it raises pressure on the victim at no risk to the group.

TermiteExtortionRetailVerification
Sev 4TargetBlue YonderActorTermiteUSA
24-1129
File

Krispy Kreme Breach Hit 161,676 People, Most of Them Its Own Staff

Not the customer of a customer. The family of an employee of the breached company.

UnattributedRetailRetail
Sev 3TargetKrispy KremeActorUnattributedUSA
24-1125
File

Starbucks and Morrisons Fell Back to Manual Processes After Blue Yonder Outage

A slower process for tinned goods costs margin. A slower process for produce costs the produce.

TermiteRetailFallback
Sev 4TargetBlue Yonder customersActorTermiteUnited Kingdom
24-1121
File

The Software That Tells the Supermarket What to Order

An American software vendor’s outage changed what was on sale in British supermarkets.

TermiteRetailThird party
Sev 4TargetBlue YonderActorTermiteUSA
24-1025
File

Hot Topic Records for 57 Million Customers Offered on a Criminal Forum

The last four digits cannot buy anything. They are what the call centre asks for.

UnattributedRetailRetail
Sev 3TargetHot TopicActorUnattributedUSA
24-0716
File

Advance Auto Parts Notified 2,316,591 People After Snowflake Theft

Applied for a job, was not hired, and handed over a social security number to be considered.

UNC5537Third-party cloud platform accessRetailRetail
Sev 4TargetAdvance Auto PartsActorUNC5537USA
24-0714
File

Rite Aid Said 2.2 Million Affected, RansomHub Claimed 45 Million

2.2 million against 45 million is not a disagreement about scope. One of them is wrong.

RansomHubRetailRetail
Sev 4TargetRite AidActorRansomHubUSA
24-0625
File

Neiman Marcus Confirmed Breach of a Cloud Database Platform

Customers learned their data had gone, and could not learn from whom.

UNC5537Third-party cloud database accessRetailRetail
Sev 3TargetNeiman MarcusActorUNC5537USA
24-0527
File

Christie’s Breach Exposed Client ID Document Numbers Over Two Days in May

A rule to collect identity documents, and no matching rule to dispose of them.

UnattributedRetailIdentity
Sev 3TargetChristie’sActorUnattributedUnited Kingdom
24-0322
File

Panera Bread Ransomware Took Tills and Ordering Down for a Week

A restaurant chain without tills is not a degraded restaurant chain.

UnattributedRetailAvailability
Sev 3TargetPanera BreadActorUnattributedUSA
24-0314
File

Giant Tiger Vendor Breach Put 2.8 Million Customer Records Online

Data for sale reaches whoever pays. Data published free reaches everyone, permanently.

UnattributedThird-party vendor compromiseRetailThird party
Sev 3TargetGiant TigerActorUnattributedCanada
23-0715
File

ALPHV and Cl0p Both Listed Estee Lauder From Separate Intrusions

An organisation dealing with an incident should not assume it is dealing with an incident.

ALPHV, Cl0pMOVEit (Cl0p); not established (ALPHV)RetailAftermath
Sev 4TargetThe Estée Lauder CompaniesActorALPHV, Cl0pUSA
23-0412
File

Ransomware at One NCR Data Centre Stopped Restaurants Running Their Own Back Office

The unit that matters is not the facility. It is the number of organisations that stop when it does.

ALPHV/BlackCatRansomwareRetailAvailability
Sev 4TargetNCR Aloha customersActorALPHV/BlackCat
23-0118
File

Yum! Brands Closed 300 UK Restaurants for a Day, Then Found Employee Data Had Gone

The customer headline and the actual victim population were different groups.

UnattributedRansomwareRetailAvailability
Sev 3TargetYum! BrandsActorUnattributedUnited Kingdom
© 2026 ForensicPost Media · the desk · newsletterGlossaryNo search logging