A threat actor claims to have breached Harrods, the world-renowned luxury department store headquartered in London, United Kingdom. The actor alleges the infiltration occurred in late September 2025, resulting in the exfiltration of a database containing information on over 433,000 customers and employees.
According to the post advertising the data for sale, the threat actor attempted to contact the company for payment but received no response.
The allegedly compromised data includes a wide range of personally identifiable information (PII). According to the actor, the exposed information includes:
- Full names
- Gender
- Dates of birth
- Email addresses
- Phone numbers
- Physical addresses
- Customer loyalty group information, indicating annual spending
- Account creation and update timestamps












