Flink hackers turn to customers after ransom demand is ignored, seek 100 ETH in total

Flink hackers turn to customers after ransom demand is ignored, seek 100 ETH in total

N
News Editor
2026-09-30 04:06:13
German grocery delivery platform Flink is dealing with a data breach that took an unusual turn after the company declined to engage with the attackers. According to heise online, the group behind the intrusion, identified in extortion emails as LPG Group, first approached Flink through a web form and demanded payment in ETH. A company spokesperson said Flink did not respond. The attackers then shifted tactics and began contacting customers directly. Their demand: 0.005 ETH from each recipient, roughly 10 euros, with a collective target of 100 ETH, or about 230,000 euros. They said the data would be deleted if the full amount was reached; otherwise, it would be sold on the dark web. Flink said the breach affected one internal Order Hub used in its city warehouse network. The company said copied data included names, delivery addresses, email addresses and phone numbers of customers and employees, with some records also containing floor details and other order-related notes. Flink said passwords, payment details, credit card data and bank information were not exposed. In the Netherlands, at least 10,000 customers received the extortion email, while the scale in Germany remains less clear.

German grocery delivery company Flink was hit by a cyberattack, and after the company declined to answer the ransom demand, the attackers began soliciting payments from customers instead.

According to German tech outlet heise online, the group behind the attack identified itself as LPG Group. The attackers initially contacted Flink through a web form and demanded payment in ETH. A Flink spokesperson said the company did not respond.

The extortion scheme then changed. Instead of seeking payment only from Flink, the attackers asked each customer to pay 0.005 ETH, described in the report as about 10 euros. If the total reached 100 ETH, or roughly 230,000 euros, they said the stolen data would be deleted. If not, the data would be offered for sale on the dark web.

One Order Hub was breached and data was copied

Flink said the attack targeted its internal order system. That system is used across its Order Hubs, the small warehouses spread through cities.

The company said only one Order Hub was compromised. Unauthorized access has been cut off, but the data had already been copied.

Leaked information includes names, delivery addresses, email addresses and phone numbers of both customers and employees. In some cases, floor details, delivery notes and other order information were also taken. Flink said passwords, payment information, credit card details and bank data were not exposed.

In its ransom note, LPG Group claimed to hold data tied to more than 1 million customers and 13,000 employees. Flink did not confirm those figures.

As described in the report, the stolen dataset appears to include where people live, which floor they are on, and how to contact them. It does not include passwords, but it could still be used to craft convincing phishing emails.

Extortion emails mimicked Flink sender details

The clearest impact so far has been in the Netherlands. Flink said at least 10,000 customers there received the extortion email.

Samples obtained by heise online show the sender naming LPG Group, a previously little-known organization. The email opened with the recipient's name and used sender details made to look very similar to Flink's own address.

In the message, LPG Group described itself as 「just doing business」 and shifted blame to Flink, saying that because the company would not pay, customers would have to. The email also included instructions on how to buy and transfer ETH and suggested recipients forward the message to Flink so the company would notice the matter.

Scale in Germany remains unclear

The size of the impact in Germany is still harder to determine. Flink said that as of Saturday, its customer service team had received about 150 customer reports. The company also said it had directly notified all customers on Friday.

Flink has reported abuse to the email service provider used by LPG Group, which has temporarily reduced the volume of messages. The company said, however, that it cannot rule out the attackers switching to another channel.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.