Harrods informs 430k customers that their personal data was stolen in new data breach

29/09/2025 | BBC News

Luxury department store Harrods has confirmed that data relating to 430,000 customer records was stolen in an IT systems breach involving a third-party provider. The company stated that the breach, which is unrelated to the cyberattack in May, was limited to basic personal information, including names, contact details, and marketing preferences.

Harrods also clarified that no payment details or passwords were accessed and stated it would not engage with the "threat actor" who contacted the company. A spokesperson said the majority of customers shop in-store, meaning only a small proportion of shoppers were affected. Harrods has informed all relevant authorities and is focused on supporting affected customers.


Training Announcement: Freevacy offers a range of independent data protection qualifications from IAPP and BCS. Our certified courses are available at foundation and practitioner levels and cover multiple legal jurisdictions, data protection operations management, and the implementation of complex privacy solutions in technical environments. Find out more.

Read Full Story
Harrods

What is this page?

You are reading a summary article on the Privacy Newsfeed, a free resource for DPOs and other professionals with privacy or data protection responsibilities helping them stay informed of industry news all in one place. The information here is a brief snippet relating to a single piece of original content or several articles about a common topic or thread. The main contributor is listed in the top left-hand corner, just beneath the article title.

The Privacy Newsfeed monitors over 300 global publications, of which more than 6,250 summary articles have been posted to the online archive dating back to the beginning of 2020. A weekly roundup is available by email every Friday.