Flink Hit by Major Data Breach: Cybercriminals Extort Customers and Employees
Cybercriminals operating under the name LPG Group claimed to have stolen personal data from Flink, the rapid grocery delivery service, affecting 1 million customers and 13,000 employees. The breach, disclosed on Friday, exposed names, postal codes, email addresses, phone numbers, and delivery instructions but not passwords, billing details, or payment card information.
Flink, headquartered in Germany with operations in the Netherlands, confirmed the incident and reported it to German and Dutch authorities, including the German Data Protection Authority. The company stated that unauthorized access to an internal system was immediately blocked, and an investigation is underway with external cybersecurity experts.
The hackers demanded €11.80 in Ethereum (0.005 ETH) from individual victims in exchange for deleting their data, while also threatening to leak all stolen data unless Flink paid 100 ETH (nearly €237,300) by October 2. Flink has not confirmed whether it received a separate extortion demand but warned customers and employees not to engage with the attackers.
The LPG Group remains largely unknown, though cybersecurity experts note similarities to Conti ransomware, a tool linked to the Russian-backed Wizard Spider hacking collective. The group’s tactic of directly extorting individual victims rather than just the company is unusual, according to Pim Takkenberg of Northwave, who called it an "exceptional" approach.
Flink, which gained popularity during the COVID-19 pandemic, serves dozens of Dutch municipalities, including 24 of the 25 largest in the country. The breach highlights a growing trend of cybercriminals targeting consumers when companies refuse to pay ransom demands.
Flink cybersecurity rating report: https://www.rankiteo.com/company/goflink
"id": "GOF1790584799",
"linkid": "goflink",
"type": "Breach",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '1000000',
'industry': 'Grocery Delivery',
'location': 'Germany, Netherlands',
'name': 'Flink',
'type': 'Company'}],
'attack_vector': 'Unauthorized access to an internal system',
'customer_advisories': 'Warned customers not to engage with attackers',
'data_breach': {'data_exfiltration': 'Yes',
'number_of_records_exposed': '1013000',
'personally_identifiable_information': 'Names, postal codes, '
'email addresses, '
'phone numbers, '
'delivery instructions',
'sensitivity_of_data': 'Medium (PII but no financial data)',
'type_of_data_compromised': 'Personal data'},
'date_publicly_disclosed': '2023-10-06',
'description': 'Cybercriminals operating under the name LPG Group claimed to '
'have stolen personal data from Flink, the rapid grocery '
'delivery service, affecting 1 million customers and 13,000 '
'employees. The breach exposed names, postal codes, email '
'addresses, phone numbers, and delivery instructions but not '
'passwords, billing details, or payment card information. The '
'hackers demanded €11.80 in Ethereum from individual victims '
'and threatened to leak all stolen data unless Flink paid 100 '
'ETH (nearly €237,300) by October 2.',
'impact': {'brand_reputation_impact': 'Yes',
'data_compromised': 'Names, postal codes, email addresses, phone '
'numbers, delivery instructions',
'identity_theft_risk': 'Yes',
'payment_information_risk': 'No',
'systems_affected': 'Internal system'},
'investigation_status': 'Ongoing',
'motivation': 'Extortion',
'ransomware': {'data_exfiltration': 'Yes',
'ransom_demanded': '100 ETH (€237,300) from Flink, €11.80 '
'(0.005 ETH) from individual victims'},
'references': [{'source': 'Cybersecurity news report'}],
'regulatory_compliance': {'regulatory_notifications': 'Reported to German and '
'Dutch authorities, '
'including German Data '
'Protection Authority'},
'response': {'communication_strategy': 'Warned customers and employees not to '
'engage with attackers',
'containment_measures': 'Unauthorized access immediately blocked',
'incident_response_plan_activated': 'Yes',
'law_enforcement_notified': 'Yes',
'third_party_assistance': 'External cybersecurity experts'},
'stakeholder_advisories': 'Warned customers and employees not to engage with '
'attackers',
'threat_actor': 'LPG Group',
'title': 'Flink Hit by Major Data Breach: Cybercriminals Extort Customers and '
'Employees',
'type': 'Data Breach'}