Coles customer credit card data caught up in Latitude Financial breach

Organization
Coles Group
Exploit
Third-Party Data Breach
Industry
Retail

Coles Group told customers in April 2023 that historical credit card data held by Latitude Financial Services had been exposed in the cyberattack Latitude disclosed the previous month. The Australian supermarket chain said the records related to its former in-house credit card programme rather than to any compromise of its own systems.

Latitude, and before it GE Money, issued Coles branded credit cards until March 2018, when Coles Financial Services moved the portfolio to Citibank. Only customers who held a card under the earlier arrangement were affected.

Coles said Latitude had not advised it of the number of impacted customers or of the specific details of the breach, and directed affected cardholders to Latitude's own incident website for guidance. The retailer said it was disappointed the incident had taken place and apologised for the inconvenience and uncertainty created.

The underlying Latitude breach was one of the largest disclosed in Australia. iTnews reported that the Latitude breach, first revealed in mid March 2023, exposed more than 14 million records, and that Latitude subsequently said it had received and rejected a ransom demand. Cyber Daily reported that Latitude put the number at 250,000 customers when it announced the breach on 16 March 2023 and revised the tally to more than 14 million on 27 March 2023.

As of the reporting date Coles had published no figure for its own affected customers, and the scope of the exposure for former Coles cardholders remained undetermined.

Sources