Royal Mail, the UK postal service, experienced a cyberattack on March 31, leading to the alleged exfiltration of 144 GB of data. Although the postal service systems remained unaffected, compromised data purportedly included confidential documents, personal customer information, delivery addresses, Zoom meeting recordings, MailChimp mailing lists, and a WordPress SQL database. An investigation is ongoing to determine the impact of the breach on Spectos, a Royal Mail supplier. Only a single email address was confirmed among the exposed data, according to Cybernews researchers, suggesting the effects may be limited.
Source: https://www.scworld.com/brief/massive-royal-mail-breach-alleged-by-threat-actors
TPRM report: https://scoringcyber.rankiteo.com/company/royal-mail
"id": "roy554040225",
"linkid": "royal-mail",
"type": "Breach",
"date": "4/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Postal Service',
'location': 'United Kingdom',
'name': 'Royal Mail',
'type': 'Organization'},
{'name': 'Spectos', 'type': 'Organization'}],
'data_breach': {'data_exfiltration': '144 GB',
'personally_identifiable_information': 'personal customer '
'information',
'type_of_data_compromised': ['confidential documents',
'personal customer information',
'delivery addresses',
'Zoom meeting recordings',
'MailChimp mailing lists',
'WordPress SQL database']},
'date_detected': '2023-03-31',
'description': 'Royal Mail, the UK postal service, experienced a cyberattack '
'on March 31, leading to the alleged exfiltration of 144 GB of '
'data. Although the postal service systems remained '
'unaffected, compromised data purportedly included '
'confidential documents, personal customer information, '
'delivery addresses, Zoom meeting recordings, MailChimp '
'mailing lists, and a WordPress SQL database. An investigation '
'is ongoing to determine the impact of the breach on Spectos, '
'a Royal Mail supplier. Only a single email address was '
'confirmed among the exposed data, according to Cybernews '
'researchers, suggesting the effects may be limited.',
'impact': {'data_compromised': ['confidential documents',
'personal customer information',
'delivery addresses',
'Zoom meeting recordings',
'MailChimp mailing lists',
'WordPress SQL database']},
'investigation_status': 'Ongoing',
'references': [{'source': 'Cybernews'}],
'title': 'Royal Mail Cyberattack',
'type': 'Data Breach'}