Hackers targeting grocery delivery company Flink have taken an unusual approach to extortion by demanding cryptocurrency payments directly from customers whose personal information was exposed in a recent data breach.

 

 

Flink confirmed that an unauthorized party gained access to one of its internal systems, exposing customer information including names, email addresses, postal addresses and telephone numbers. Some affected records also contained delivery details such as floor numbers, names displayed on doorbells and individual delivery instructions.

The company said passwords were not compromised. Billing information, bank account details and payment card information were also unaffected, according to Flink.

A newly emerged cybercrime operation calling itself LPG Group has claimed responsibility for the attack. The group says it obtained information belonging to more than one million Flink customers and 13,000 employees, although Flink has not confirmed those figures.

Instead of limiting its pressure campaign to the company, LPG Group has started contacting individuals whose information was allegedly stolen. Customers have received emails demanding 0.005 ETH, worth roughly €10 to €12 at the time of reporting, in exchange for keeping their information from being sold on the dark web.

The attackers have also demanded 100 ETH from Flink, worth approximately €238,000, and claim they will delete the stolen information if the larger payment is made. Their messages give victims an October 2 deadline and encourage recipients to forward the ransom demand to Flink to increase pressure on the company.

This approach adds another layer to the traditional ransomware extortion model. Rather than relying only on pressure against the breached organization, the attackers are attempting to turn its customers into additional sources of ransom payments while simultaneously using their concerns to pressure Flink.

Flink says it is aware that criminals are contacting customers and employees and has explicitly warned affected individuals not to respond or send money.

The company blocked the unauthorized access after discovering the incident and introduced additional security measures. External IT forensic and cybersecurity specialists are assisting with an investigation into the breach.

Flink has also reported the incident to Germany’s data protection authority and law enforcement, with reports filed with police in Germany and the Netherlands.

How the attackers initially obtained access remains less certain. Reporting has linked the intrusion to compromised employee credentials, but Flink has not publicly provided a detailed technical explanation of how those credentials were obtained.

Leave a Reply