LiMP VPN
← All news

Flink Hack: Hackers Steal Data of 1 Million Customers

Flink Hack: Hackers Steal Data of 1 Million Customers

In short: On September 25, 2026, it emerged that a little-known group calling itself LPG Group had stolen personal data belonging to more than a million customers of quick-commerce grocery delivery app Flink in Germany and the Netherlands, along with records on 13,000 staff. The attackers didn't stop at extorting the company — they also contacted individual users directly, offering to delete their personal record for a fee. Passwords, billing details, and card numbers were not among the stolen data, according to Flink.

What happened

Flink is a popular European ultrafast grocery delivery service, similar to quick-commerce apps elsewhere. According to LPG Group, the stolen data includes names, postal codes, email addresses, phone numbers, and delivery instructions for over a million customers, plus records on 13,000 employees. If you use several delivery or shopping apps, it's worth checking whether your own personal data has appeared in a leak before — it only takes a couple of minutes.

Flink confirmed the incident, saying access was blocked immediately, additional security measures were put in place, and an investigation with external experts is underway. The company notified Germany's data protection authority and law enforcement in both Germany and the Netherlands.

Double extortion: pressuring the company and its customers directly

LPG Group used a double-pressure scheme typical of modern extortion attacks. The group demanded roughly 100 ETH (about €237,000 at the time) from Flink itself to delete the entire stolen dataset. In parallel, some affected customers and employees received personal messages demanding around €11.80 each for "individual" deletion of their own record.

Flink officially warned customers and staff not to respond to these messages or send any money: payment guarantees neither that data will actually be deleted nor that copies won't remain with the attackers or get resold to third parties.

What this means for ordinary users

Even without passwords or card numbers, the combination of name + phone + email + delivery address is a ready-made toolkit for targeted phishing, fake "bank security" calls, and social engineering. It's the same pattern we covered in the telecom customer email breach story: the more precise the data a scammer has on you, the more convincing their next call or email sounds. What's distinct here is the direct contact between the hackers and rank-and-file users demanding payment — that's not a data-deletion guarantee, it's an attempt to monetize the victim's fear directly, bypassing the company entirely.

How to protect yourself

If you're a Flink customer (or use a similar delivery service in Europe), don't reply to messages demanding payment for data deletion and don't click any links in them — that's a classic phishing channel disguised as incident "resolution." Check whether your Flink email was reused to register on other services, and change passwords anywhere you used a similar combination. It's also worth periodically checking which apps on your phone are actually collecting your data — for example, via an installed-apps audit. Encrypting your traffic with LiMP VPN won't stop a breach on the delivery service's side, but it protects your logins and messages from interception while you're sorting out the fallout on untrusted networks.

Sources