Skip to content
Individuals sent ransom notes after cybercriminals steal Flink customer & worker data

Individuals sent ransom notes after cybercriminals steal Flink customer & worker data

Nltimes.Nl • September 25, 2026

Cybercriminals claimed on Friday that they managed to steal personal information pertaining to a million customers of rapid grocery delivery service Flink, as well as the data of 13,000 workers. The company told NL Times that it is also aware of people being contacted directly by the computer hacker collective to extort money from affected people in exchange for the deletion of their data.

Personal details have been stolen regarding names, postal codes, email addresses, and phone numbers, as well as delivery instructions. Flink stressed that account passwords, billing information, bank account details, and payment cards were not compromised. The total number of affected customers was not confirmed by Flink, but one million would represent two-thirds of their customer base, according to information Flink released in June. The company is contacting customers in both the Netherlands and Germany.

Flink has reported the matter to the German Data Protection Authority, and has filed reports with police there and in the Netherlands, a company spokesperson said. Flink is headquartered and operates in Germany, and has a Dutch corporation with an address in Amsterdam. Since its founding five years ago, the company started up and wound down operations in both Austria and France. The spokesperson said Flink will cooperate fully with investigative agencies.

"Unauthorized individuals have gained access to data in one of our internal systems. We take this incident very seriously. The access in question was immediately blocked, additional security measures have been taken, and a comprehensive investigation has been launched in collaboration with external forensic IT and cybersecurity experts," the company stated.

Emails sent from a cybercrime organization calling itself LPG Group to alleged victims of the scam included a demand for the equivalent of 11.80 euros in the cryptocurrency, Ethereum, amounting to 0.005 ETH. The group said it will "delete all user data" if the company itself pays an extortion demand of 100 ETH, which is just shy of 237,300 euros. A deadline of Oct. 2 was mentioned in the email.

Flink would not say if they also received a separate extortion demand. "We are aware that criminals are currently attempting to exploit this incident by contacting customers and employees directly and requesting payments. We strongly advise against responding to such messages, and making any payments," the company said by email.

"Our first priority is protecting our customers and employees, their data, and directly informing everyone who may have been affected by the incident. To avoid obstructing the authorities' investigation, we cannot further details at this time," the company stated.

The LPG Group is not particularly well-known, and their origins have not yet been reported. An earlier ransomware method linked to the Conti malware system developed by Russian-backed hacking group Wizard Spider uses a file disguised by the name lpg.dll to gain access into systems. The malicious software is linked to Ransomware-as-a-Service attacks where the victim's data is encrypted until they pay a demanded sum.

Cybersecurity expert Pim Takkenberg said the attempt to extort victims as if it were a crowdfunding campaign is exceptional. Hacker group Shinyhunters did extort Dutch higher education institutions that were the clients of a hacked software system.

"But I haven't seen individual consumers being approached before," said Takkenberg in an interview with NOS. The expert works for cybersecurity firm Northwave.

RTL Nieuws tech journalist Daniël Verlaan also remarked that more companies are refusing to pay ransom demands from cyber criminals. This may indicate a "new manner of generating revenue" when an organization refuses to pay. "It is remarkable for cybercriminals to extort a company's customers," he stated.

Flink may be LPG Group's first actual victim. The rapid delivery service and dark grocery store rose in popularity during the coronavirus pandemic, and still serves dozens of municipalities in the Netherlands including 24 of the 25 largest in the country.

Extracted Entities

APT Groups (1)

Attack Types (1)

Companies (1)

Ransomware Groups (1)