German grocery delivery company Flink was hit by a cyberattack, and after the company declined to answer the ransom demand, the attackers began soliciting payments from customers instead.
According to German tech outlet heise online, the group behind the attack identified itself as LPG Group. The attackers initially contacted Flink through a web form and demanded payment in ETH. A Flink spokesperson said the company did not respond.
The extortion scheme then changed. Instead of seeking payment only from Flink, the attackers asked each customer to pay 0.005 ETH, described in the report as about 10 euros. If the total reached 100 ETH, or roughly 230,000 euros, they said the stolen data would be deleted. If not, the data would be offered for sale on the dark web.
One Order Hub was breached and data was copied
Flink said the attack targeted its internal order system. That system is used across its Order Hubs, the small warehouses spread through cities.
The company said only one Order Hub was compromised. Unauthorized access has been cut off, but the data had already been copied.
Leaked information includes names, delivery addresses, email addresses and phone numbers of both customers and employees. In some cases, floor details, delivery notes and other order information were also taken. Flink said passwords, payment information, credit card details and bank data were not exposed.
In its ransom note, LPG Group claimed to hold data tied to more than 1 million customers and 13,000 employees. Flink did not confirm those figures.
As described in the report, the stolen dataset appears to include where people live, which floor they are on, and how to contact them. It does not include passwords, but it could still be used to craft convincing phishing emails.
Extortion emails mimicked Flink sender details
The clearest impact so far has been in the Netherlands. Flink said at least 10,000 customers there received the extortion email.
Samples obtained by heise online show the sender naming LPG Group, a previously little-known organization. The email opened with the recipient's name and used sender details made to look very similar to Flink's own address.
In the message, LPG Group described itself as 「just doing business」 and shifted blame to Flink, saying that because the company would not pay, customers would have to. The email also included instructions on how to buy and transfer ETH and suggested recipients forward the message to Flink so the company would notice the matter.
Scale in Germany remains unclear
The size of the impact in Germany is still harder to determine. Flink said that as of Saturday, its customer service team had received about 150 customer reports. The company also said it had directly notified all customers on Friday.
Flink has reported abuse to the email service provider used by LPG Group, which has temporarily reduced the volume of messages. The company said, however, that it cannot rule out the attackers switching to another channel.

