In brief: Intruders copied data from an internal system at grocery-delivery company Flink and are now demanding money directly from individual customers. Flink confirms the breach, but not the victim count claimed by the attackers. The method combines a conventional data theft with credible, personalised mass extortion.
Confirmed: contact data stolen, payment data unaffected according to Flink
Flink says the attackers entered an internal system using credentials belonging to a former employee. The company blocked the access, notified data-protection authorities and police, and brought in external forensic specialists.
Flink's current findings cover names, email addresses, postal addresses and phone numbers. The company cannot fully exclude additional order information such as floor numbers, doorbell names or delivery instructions. It says passwords, bank details and payment-card data were not compromised.
The attackers address customers by name and demand 0.005 Ether per account. They also promise to delete all data once payments total 100 Ether. Their claim of one million customers and 13,000 employees is not confirmed by Flink. Any promise to delete copied data would also be technically unverifiable.
Pandorex Analysis: shifting pressure to personalised micro-demands
The unusual element is not the theft itself but the distribution of extortion. Instead of pressuring only the company, the group uses confirmed identity and address data to seek many small individual payments. A low amount reduces friction, while the shared 100-ETH target makes the scheme resemble collective funding.
A correct address therefore makes the threat credible, but does not show that paying provides protection. Flink advises recipients not to reply or pay. Affected people should preserve the message, including sender and header data, remain alert to calls or emails containing delivery details, and report a personal demand to police.
Golem and NL Times distinguish Flink's confirmed data categories from the attackers' unverified million-user figure. Tagesspiegel additionally records the former employee credential as the entry point. The core account is consistent, while the scale and any additional order data remain under investigation.
