Menu
Browse

Cyber Incident Victim: Spar SA

Date:

May 2025

Location:

Poland

Summary

Spar SA experienced a hacker attack that resulted in unauthorized access to its online store systems and the exposure of customers’ personal data, including names, surnames, phone numbers, email addresses and delivery addresses. The breach raised the risk of unwanted telephone contacts, telemarketing and fraud attempts using the stolen information. In response, the company secured its IT infrastructure, identified and blocked the source of the intrusion, and notified the data protection authority.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On 21 May 2025, unauthorized access to the IT systems of WSS Detal Sp. z o.o., operator of the online Spar store, resulted in a data breach. The breach exposed personal data consisting of customers' names, surnames, telephone numbers, email addresses, and delivery addresses used for orders. The article notes that the delivery addresses may also correspond to customers' home addresses. The incident was discovered on the same day and reported as a personal data protection violation under Article 34 of GDPR.

Cyber Incident Image

The exposed data could be used for unwanted telephone contact, including telemarketing and fraud attempts. Attackers possessing the full set of data might try to defraud money or direct victims to counterfeit websites, increasing credibility by using genuine personal details from the leak. The company warned that such misuse could lead to unwanted calls concerning personal or financial matters.

The company secured access to its IT systems, identified and blocked the source of the unauthorized access, and notified the President of the Office for Personal Data Protection (UODO) of the incident. It also informed affected customers via a communication that included the contact address [email protected] for reporting any misuse and for contacting the legal office. The company declared that it had fulfilled all formal obligations related to the breach and would make every effort to prevent a similar event in the future.

Sources
Sources available to members
2 sources