Samsung UK store breach exposed contact details of 2019 and 2020 shoppers
- Organization
- Samsung Electronics
- Exploit
- Hacking
- Industry
- Consumer Electronics
Samsung Electronics told UK customers in November 2023 that their personal details had been exposed in a breach affecting its UK online store. The company said it identified the problem on November 13, 2023, after an unauthorized individual exploited a vulnerability in an unnamed third party business application it used.
The exposure covered people who bought from the Samsung UK store between July 1, 2019 and June 30, 2020, meaning the compromised records were more than three years old by the time customers were told. Samsung did not say when the intrusion began or how long the attacker had access.
The affected data was limited to names, telephone numbers, postal addresses and email addresses. Samsung said no financial information such as bank or payment card details was involved, and that customer passwords were not affected.
The company said it had taken the steps needed to resolve the security issue, reported the incident to the UK Information Commissioner's Office and contacted affected customers directly. It did not publish a figure for how many people were affected, and said the incident was confined to UK e-commerce customers, with no data belonging to customers, staff or retailers elsewhere involved. It was the third security incident Samsung had disclosed in roughly two years.