CSIDB logo
Incident

Hemmakvall AB

Incident posture

Attack window
Aug 2015
Location
Sweden
Status
Historical
CIA posture
Available to members
Updated
2026-01-13 23:03

Linked entities

Victim
Hemmakvall AB
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Aug 2015
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A Swedish video rental chain experienced a significant cybersecurity breach resulting in the compromise of nearly 50,000 customer records. Sensitive data including encrypted passwords and personal information was exposed and subsequently disseminated openly online, posing substantial risks to affected individuals. The incident involved unauthorized access to the company's customer registry, highlighting vulnerabilities in safeguarding consumer data.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On August 7, 2015, Swedish video rental chain Hemmakvall AB publicly faced a significant cybersecurity incident involving unauthorized access to its customer database. Attackers compromised the company’s systems, extracting a customer registry containing personal information belonging to approximately 50,000 individuals. The stolen dataset included sensitive customer details alongside encrypted passwords, indicating a breach of authentication or customer management systems. The attackers subsequently disseminated this data openly across the internet, exposing affected customers to potential identity theft, credential misuse, and secondary targeting. No specific technical details regarding the intrusion method—such as malware, phishing, or exploited vulnerabilities—were disclosed in available reporting. The incident represented a direct compromise of Hemmakvall’s data storage infrastructure, though the duration between initial breach and public disclosure remained unclear.

The exposure placed tens of thousands of customers at immediate risk due to the circulation of their personal information in unsecured online environments. While encrypted passwords theoretically offered some protection against direct credential harvesting, the breach still necessitated widespread password resets and vigilance against credential-stuffing attacks targeting other services. Hemmakvall’s public acknowledgment of the breach coincided with the data’s appearance online, though the company did not initially specify containment measures, forensic findings, or customer remediation steps such as credit monitoring. The incident damaged consumer trust in Hemmakvall’s data stewardship amid broader industry concerns over retail sector cybersecurity. No follow-up disclosures regarding attacker attribution, financial impacts, or regulatory penalties were evident in the immediate aftermath.

Sources

Sources available to members: 1 source.

CSIDB