Particle.news

Flink Customers Receive Direct Extortion Emails After Data Breach

Attackers are asking customers for small Ethereum payments in exchange for alleged deletion of stolen contact and delivery data.

Overview

  • Flink confirmed on Monday that attackers copied personal contact and delivery records from an internal Order Hub but said no passwords or payment card data were taken.
  • After Flink refused an initial ransom demand, the perpetrators began emailing customers and employees individually, asking for 0.005 ETH (about €11.50) per person and claiming a 100 ETH total goal to delete the data.
  • At least 10,000 customers in the Netherlands have reported receiving extortion emails and reports cite an unverified figure of roughly 1 million customers and 13,000 employees in the dataset.
  • Investigators say the intrusion may have used compromised credentials from a former employee, prompting Flink to stop access, hire external forensics, notify data‑protection authorities and file a police report.
  • Security experts urge victims not to reply or pay because payment does not guarantee deletion and stolen contact data raise the risk of targeted phishing while affected people may explore GDPR-based compensation claims.