Lakeland hack results in breach of two encrypted databases
Kitchenware retailer confirms breach, but stops short of revealing what kind of data hackers accessed.

Kitchen cookware retailer Lakeland has fallen victim to a "sophisticated and sustained" attack by hackers, resulting in two encrypted databases being accessed.
The security breach was discovered late on Friday 19 July, the company confirmed in a statement on its website yesterday.
At the time of writing, the firm said there is no evidence to suggest the hackers stole any data.
We only wish those responsible used their talent for good rather than criminal ends.
"However, we have decided that it is safest to delete all the customer passwords used on our site and invite customers to reset their passwords," read the statement, signed by the company managing director Sam Rayner.
"Next time you log-in to your Lakeland account you will be asked to reset your password and provide a new one [but] it is not necessary to do this straight away."
The company reportedly has 64 stores across the UK, and also offers customers the option to buy its products through mail order or online shopping operations.
The hack is only thought to have affected its web-based business at this time.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The statement then goes on to advise customers that use their Lakeland password for other online accounts to change their login credentials as soon as possible.
"We do not know for certain the hackers succeeded in stealing data, however since there is a theoretical risk and because it is our policy to be open and honest with our customers, we are being proactive in alerting you," it added.
Lakeland said the cyber attack was made possible by a recently identified flaw in the server system used to run its website, which is overseen by an unnamed third-party IT company.
"This occurred despite the best efforts of ourselves and the industry leading IT company that runs our website for us," the statement continued.
"This flaw was used to gain unauthorised access to the Lakeland web system and data...[and] hacking the Lakeland site has taken a concerted effort and considerable skill.
"We only wish those responsible used their talent for good rather than criminal ends," it concluded.
Dodi Glenn, director of security content management at infosecurity firm ThreatTrack Security, said Lakeland customers have a right to know exactly what data has been compromised.
"Lakeland should work with the authorities to identify what information was leaked. Customers should have the right to know if their credit card numbers were stolen," said Glenn.
"Lakeland and others should take note that being proactive instead of reactive is the best approach, because brand reputation is priceless."
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
P2PInfect self-replicating Rust worm discovered attacking Redis instances
News Researchers believe that the worm could be laying the groundwork for a larger campaign to be launched at some point in the future
By Rory Bathgate Published
-
Redefining modern enterprise storage for mission-critical workloads
Whitepaper Evolving technology to meet the mission-critical needs of the most demanding IT environments
By ITPro Published
-
MWC 2023: Huawei launches 'world's best' ransomware detection system
News Huawei claims its Cyber Engine database security system has a 99.9% detection rate, but experts have been quick to weaken the sentiment
By Bobby Hellard Published
-
Dutch hacker steals data from virtually entire population of Austria
News The data was stolen from a misconfigured cloud database found by the attacker through a search engine
By Zach Marzouk Published
-
IRS mistakenly publishes 112,000 taxpayer records for the second time
News A contractor is thought to be responsible for the error, with the agency reportedly reviewing its relationship with Accenture
By Zach Marzouk Published
-
Database and big data security
Whitepaper KuppingerCole 2021 Leadership Compass Report
By ITPro Published
-
Modernise your legacy databases in the cloud
Whitepaper An introduction to cloud databases
By ITPro Published
-
Microsoft Azure flaw exposed 'thousands' of customer databases
News Security research Wiz describes Cosmos flaw as "the worst cloud vulnerability you can imagine"
By Bobby Hellard Published