Carpetright cyberattack halts UK store and online trading for a week
- Organization
- Carpetright
- Exploit
- Hacking
- Industry
- Retail
Carpetright, the UK flooring retailer, was knocked out of trading for close to a week in April 2024 after malware reached systems at its head office in Purfleet, Essex. The company said the intrusion gave attackers unauthorised access to internal systems before it was contained.
The disruption reached the retailer's full estate of roughly 400 stores. Customers could not place orders in branches or through the website, and fulfilment slipped for those who had already bought. Around 3,000 staff were unable to reach payroll information while systems were offline, and customer service phone lines were affected as well.
Carpetright said it isolated the malware quickly and that no customer or employee data appeared to have been taken. "We are not aware of any customer or colleague data being impacted by this incident and are testing and resetting systems, with investigations ongoing," the retailer said in a statement reported by Retail Gazette. The company did not identify the malware family or explain how it entered the network.
Management aimed to resume trading around 24 April. Analysts noted the timing was difficult for the business: the UK floorcoverings market was already forecast to contract by about 2.5% in the first half of 2024, and a week-long outage risked pushing shoppers toward competitors. As of late April the retailer was still testing and resetting systems, with its investigation continuing.