Observed Signal · Sep 28, 2026 · Data Breach · Source: t3n · Impact: 3/5 · Sentiment: Negative

Cyberattack on Flink: Hackers Demand Ransom Directly from Customers

Executive Signal Summary

After a cyberattack on the German rapid delivery service Flink, hackers have stolen personal data of about one million customers and 13,000 employees. Because Flink refused to negotiate or pay a ransom, the attackers are now directly contacting individual customers via email, demanding 0.005 Ether (about €11.50) to prevent data sale. This 'triple extortion' tactic is unusual in German-speaking regions. The stolen data includes names, email addresses, postal addresses, and phone numbers, potentially also delivery-related details. Flink has stopped the breach, which occurred through a former employee's compromised account, and is cooperating with forensic experts and authorities. Legal experts note that customers may claim damages under GDPR, especially after a recent German Federal Court ruling that loss of control over personal data alone constitutes compensable damage.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

This article is relevant to the AdTech industry as it involves a data breach at a consumer delivery service, highlighting risks of customer data exposure and potential impacts on customer trust and data privacy regulations, which are crucial for advertising and marketing technologies.

SIGNAL RADAR

Track Flink Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Hackers stole personal data of about 1 million customers and 13,000 employees from Flink.
  • Flink refused to pay ransom, leading attackers to demand 0.005 Ether (approx. €11.50) directly from customers.
  • The breach occurred via a former employee's compromised internal account.
  • Stolen data includes names, email addresses, postal addresses, and phone numbers; no passwords or financial data compromised.
  • Flink is cooperating with IT forensics experts and has informed data protection authorities.

Connected Companies & Entities

1 Entity mapped

“Nach einem Cyberangriff auf den Schnelllieferdienst Flink haben Kriminelle offenbar persönliche Daten von Kund:innen und Mitarbeitenden erbe...”

Ontology Mapping & Concepts

Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: t3n•Published: Sep 28, 2026
Original Coverage Title: “Nach Cyberangriff auf Flink: Hacker fordern Lösegeld direkt von Kunden”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Cybersecurity / Data BreachSep 25, 2026

Flink Data Breach: Delivery Service Warns of Phishing and Extortion

German quick-commerce delivery service Flink has alerted customers to a data breach after an unauthorized person accessed one of its internal systems using compromised credentials. The incident was detected on Friday, and the affected access was promptly deactivated. An investigation with external IT forensics and cybersecurity experts is underway. Potentially exposed data includes names, email addresses, postal addresses, phone numbers, and, possibly, delivery-related information such as floor, entrance, and special delivery instructions. The company states that passwords and payment information are not affected. Flink warns customers about potential phishing and extortion attempts following the breach and advises them not to make any payments, as the company will never request money or cryptocurrency. Authorities have been notified, and criminal charges have been filed.

Read assessment
Data BreachJun 25, 2026

Klue Hack: Stolen Customer Data Being Deleted, New Threats

Market research provider Klue confirmed a June 12, 2026 breach in which attackers stole customer data and authentication keys. Klue says it is communicating with the threat actor known as “Icarus,” which told the company it is taking steps to delete stolen customer data and that the Icarus site is down. Klue also warned customers that a second, unnamed gang is attempting to extort Klue’s customers directly after claiming to obtain samples of data from Icarus; that group published a list and demanded ransom, claiming 195 affected customers. Klue reported attackers used a 2022 third-party credential (from a limited pilot) to access systems and exfiltrate OAuth tokens that allowed login to customer clouds and databases.

Read assessment
SecurityMay 18, 2026

Grafana Labs: Hackers Stole Code, Company Refuses Ransom

Grafana Labs confirmed a security incident in which attackers used a stolen token credential to access the company’s GitLab environment and obtain its source code repositories. The company said the token did not grant access to customer records or financial data; it has since invalidated the token and implemented additional security measures. Attackers attempted to extort Grafana by threatening to publish the codebase, but Grafana refused to pay, citing law‑enforcement guidance. It remains unclear whether any proprietary or non-public code was taken. Grafana’s investigation is ongoing and the company said it will publish findings when the probe concludes. The report contrasts Grafana’s refusal to pay with a separate recent incident in which education‑tech firm Instructure reached an agreement to pay attackers.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.