Harrods said on 26 September 2025 that some e-commerce customers’ personal data had been taken from a third-party provider’s system. The retailer said the information included names and contact details, but not account passwords or payment details. The incident was not connected to the separate security event at Harrods in May 2025.
What happened in the Harrods data breach?
Harrods said it was notified by a third-party provider that personal data belonging to some Harrods e-commerce customers had been taken from one of the provider’s systems. The Guardian reported the company’s statement on 26 September 2025. The provider was not named in the reporting, and the available accounts do not establish how the data was accessed.
Harrods said the provider described the incident as isolated and contained. The retailer said it had informed affected customers and notified relevant authorities. Those notifications do not amount to a public finding by a regulator or law-enforcement agency.
What information was taken?
Harrods said the affected information was limited to basic personal identifiers, including names and contact details. It said account passwords and payment details were not included. Later reporting also quoted Harrods as saying order history had not been accessed.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problems#1 Best Overall
ITPro reported that affected records might contain labels relating to marketing and services delivered by Harrods. Harrods reportedly said an unauthorised third party was unlikely to interpret those labels accurately. The reporting does not establish that every record contained the same fields.
How many customer records were affected?
ITPro reported that 430,000 customer records were stolen from the provider. This is a reported count of records, not a confirmed count of unique people. The available reporting does not establish whether the records were all associated with different customers or whether they contained identical types of information.
Is this the same as the Harrods incident in May 2025?
No. Harrods said the provider incident was not connected to the May 2025 event. In May, Harrods restricted internet access across its sites as a precaution after an attempt to gain unauthorised access to Harrods’ own systems. The September report concerned data taken from a third-party provider’s system.
| September 2025 provider incident | May 2025 security event |
|---|---|
| Harrods said personal data for some e-commerce customers was taken from a third-party provider’s system. | Harrods restricted internet access across its sites as a precaution after an attempt to gain unauthorised access to its own systems. |
| Harrods said the information included names and contact details. | The reporting describes precautionary access restrictions; it does not establish that customer data was taken in that event. |
| Harrods said it was unrelated to the May event. | Harrods said it was unrelated to the September provider incident. |
What should affected customers know?
Customers who received a notification from Harrods can use it to confirm whether the retailer identified their information as affected. Based on Harrods’ public description, passwords and payment details were not included in this incident, so the reports do not indicate that customers need to change a Harrods password or replace a payment card because of this breach. As a general precaution, customers should be wary of unsolicited messages that use personal details to appear legitimate, and should verify account or payment requests through Harrods’ official channels rather than links in unexpected messages.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →What is still unknown?
- The third-party provider’s identity has not been established in the cited reporting.
- The technical vulnerability or method used to obtain the data has not been reported.
- The number of unique people represented by the reported records count is unknown.
- No public regulatory or law-enforcement finding on this specific incident is reported; Harrods said relevant authorities had been notified.
Harrods later said it had received communications from the threat actor and would not engage, according to ITPro’s 29 September 2025 report. The reporting does not provide a public finding that resolves the unknowns above.
Quick Recap
Best Value
Sources
- The Guardian, 26 September 2025: Harrods warns customers their data may have been stolen in IT breach
- ITPro, 29 September 2025: Harrods rejects contact with hackers after 430,000 customer records stolen from third-party provider
- Associated Press, 27 September 2025: Reporting on the incident and its distinction from the May event
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




