Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

Harrods Says Hackers Contacted It After Third-Party Breach Exposed 430,000 Customer Records

By TheFinanceBase Team5 min read

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Harrods said data from about 430,000 e-commerce customer records was stolen from a third-party provider, and that it would not engage with the threat actor who later contacted the retailer. The reported data included names and contact details; Harrods said passwords and payment details were not affected and that no Harrods system was compromised.

What happened in the Harrods data breach?

Harrods disclosed the incident on September 26, 2025, after a third-party provider told the retailer that customer data had been taken from one of the provider’s systems. Harrods then warned affected e-commerce customers. Later reporting put the scale at approximately 430,000 customer records. Treat that as a reported record count, not proof that 430,000 distinct people were affected.

The threat actor subsequently contacted Harrods. The retailer said it would not engage. Harrods did not disclose what the contact contained, and the provider was not publicly identified in the reporting. ITPro’s reporting and The Guardian’s report on the customer warning describe the disclosure and the information Harrods said was involved.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What information was exposed?

Reported exposed Harrods said was not affected Not publicly established
Names and contact details, where supplied; later reporting also referred to labels linked to marketing or services Account passwords and payment details; financial information was also reported as unaffected The provider’s identity, exact dataset and attack method; whether data was published or sold; and whether a ransom demand was made

The reported categories come from Harrods’ public position as relayed by news outlets, not a published forensic inventory. The exact records and any associated labels have not been fully set out publicly. For that reason, it would be too broad to say that every customer’s data was identical, or that all account risks have been eliminated.

Was Harrods itself hacked?

According to Harrods, no: the data was taken from a third-party provider’s system, not from a compromised Harrods system. That distinction describes where the breach occurred; it does not make the customer impact any less real. Suppliers may process information for a retailer even when they do not operate its main website or internal network.

Harrods’ privacy policy says it uses third parties for activities including website management, validating contact details, order delivery and marketing or digital services. It also describes information-security assessments for third parties handling personal data on its behalf. The policy does not identify the provider involved in this incident.

A supplier breach also does not, by itself, establish that either the retailer or supplier broke the law. Assessing responsibility would require facts about their respective roles, contractual and security controls, the data and access involved, and any regulatory findings. The cited public reporting does not answer those questions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why did the hackers contact Harrods—and why did it refuse to engage?

In data-theft incidents, criminals may contact an organisation to seek payment or threaten to publish, sell or otherwise misuse stolen data. That is general context, not a confirmed account of what happened here. Harrods did not disclose the content or purpose of the threat actor’s communications, so there is no confirmed ransom demand or public threat to release the data in the reporting cited here.

Refusing to negotiate can be one element of an incident-response strategy: payment cannot guarantee deletion or secrecy, and an initial payment may not prevent further demands. Organisations may also need to prioritise containment, investigation, customer notification and coordination with authorities. Those are possible considerations, not a statement of Harrods’ internal reasoning. A decision about contact or payment depends on the circumstances and legal and operational advice; a refusal to engage does not, on its own, prove that every consequence has been contained.

Is this connected to the May 2025 retail attacks?

Harrods said the September third-party-provider breach was separate from an attempted intrusion in May 2025, when the retailer restricted internet access across its sites as a precaution. The May incident occurred during a wider period of attacks involving major UK retailers, including Marks & Spencer and Co-op. ITV reported Harrods’ statement distinguishing the incidents.

Four people were arrested in July 2025 in connection with suspected cyberattacks involving Marks & Spencer, Co-op and Harrods, according to the Associated Press. Arrests are not convictions and do not show that those people were responsible for the September provider breach. The public statements cited here do not establish an identity for the September attackers or link them to a named group.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should Harrods customers do?

With passwords and payment details reportedly outside the affected data, there is no basis in the available reporting to say every customer needs a new card or an emergency password reset. The more immediate concern is that names and contact details can make fraudulent messages and calls feel convincing.

  1. Be wary of unexpected messages. A scammer may claim there is a Harrods delivery problem, refund, payment failure, account-verification request, or loyalty reward. Do not use links or phone numbers supplied in an unsolicited email or text; contact Harrods through a channel you locate independently.
  2. Do not disclose security information. Do not give anyone who contacts you a password, one-time code, payment details or identity documents. Knowing your name or email address does not prove that a message is genuine.
  3. Change reused passwords as a precaution. Harrods passwords were not reported as exposed. But if you reused the same password on another service, replace it there with a strong, unique one. Enable multifactor authentication on important accounts where available, especially email and banking.
  4. Monitor accounts normally. Check card and bank statements for unauthorised activity, but payment details were reported as unaffected, so card replacement is not automatically warranted. Contact your bank promptly if you spot a transaction you did not make.
  5. Keep evidence of suspicious contact. Save the message, screenshots, sender details, phone number and links rather than replying or deleting it immediately. Use current official UK reporting routes for suspected scams, such as the reporting guidance published by the National Cyber Security Centre and Action Fraud.

The UK NCSC explains that information exposed in a breach can help criminals make phishing more credible. The NCSC guidance for individuals and families and the ICO’s breach-response advice support vigilance, strong unique passwords and precautions against identity misuse.

What remains unknown?

The provider’s identity, the precise attack method, the full scope of the records, the attackers’ identity, the content of their communications and any ransom demand have not been established in the cited public reporting. It also does not establish whether the data was published or sold, or what regulatory steps followed. The ICO publishes datasets of self-reported personal-data-breach cases, but the absence of a case from a public dataset would not by itself prove that no notification or investigation occurred.

The broader lesson is that customer-data security extends beyond a retailer’s own systems. A supplier can hold information that customers entrusted to the retailer, so vendor access, data minimisation, security oversight and incident notification all matter. The public facts here explain the route of exposure, but are not enough to judge whether any particular security or legal duty was breached.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.