Royal Mail data leaked after breach at supplier Spectos

Organization
Royal Mail Group
Exploit
Third-Party Data Breach
Industry
Postal and Logistics

In late March 2025, a user of the BreachForums cybercrime site calling itself GHNA advertised roughly 144GB of data said to belong to Royal Mail Group. The archive was described as 293 folders containing 16,549 files, and the actor claimed responsibility for the theft on March 31.

The material did not come from Royal Mail's own network. Both companies traced it to Spectos GmbH, a German supplier that monitors postal service quality for Royal Mail. On April 2 Spectos said unauthorized access to its systems and to personal customer data had occurred, adding that it had engaged external cybersecurity experts and had no indications of an internal attack.

Reporting by The Register and Infosecurity Magazine described the leaked files as including names, phone numbers and addresses of senders and recipients, package and delivery datasets, post office location data, a Mailchimp mailing list, a WordPress SQL database for mailagents.uk and recordings of Zoom meetings between Spectos and Royal Mail staff.

Hudson Rock co-founder and chief technology officer Alon Gal attributed the intrusion to credentials taken from a Spectos employee by Raccoon infostealer malware in 2021 and never changed, which he said GHNA reused years later.

Royal Mail said it was working with Spectos to establish what impact there might be and that there had been no effect on its operations. It later stated that it does not send personal customer or financial data to Spectos.

Sources