DE Photo hit by back-to-back intrusions over Christmas 2024

Organization
DE Photo
Exploit
Hacking
Industry
Photography Services

DE Photo, a UK company that shoots school, sports club and event photography, disclosed that an attacker broke into its systems over the Christmas 2024 holiday and returned four days later, after the first intrusion had supposedly been cleaned up.

The company said the initial compromise happened on December 26, 2024. Its IT team took the affected systems offline and changed administrative passwords, but the intruder regained access on December 29. DE Photo then shut its servers down entirely and brought in outside forensic investigators.

An actor using the handle 0mid16B claimed responsibility and gave DataBreaches.net figures the company has never endorsed: records for 555,952 customers, 429,597 orders, and 16,213 entries said to contain full payment card numbers and CVV codes, alongside hundreds of gigabytes of photographs. The same account said a 50,000 pound ransom demand was sent to a company developer over WhatsApp and ignored.

DE Photo's public notice describes a narrower exposure: names, addresses, phone numbers and email addresses, with "no usable payment information or passwords" compromised, because card transactions are handled by Stripe and PayPal rather than stored in house. The company reported the incident to the Information Commissioner's Office and Action Fraud and began emailing customers around December 28. It later said replacement systems went live on March 18, 2025 and that a suspect was arrested on February 26, 2025.

Sources