Funky Pigeon site offline after "cyber incident"
The WH Smith-owned card site has reported the breach to "the relevant regulators"


Online greeting cards business Funky Pigeon has stopped taking orders after it was hit by a cyber attack.
The company became aware of the incident last Thursday and said it has informed "the relevant regulators" about the breach.
UK retailer The Works suffers ransomware attack leading to store closures IT Pro News In Review: The Works cyber attack, Lenovo recruitment drive, old macOS vulnerabilities Travelex services forced offline by cyber attack
Funky Pigeon is owned by WH Smiths, and the retailer confirmed that it had taken the system offline, "as a precaution", and is, therefore, unable to fulfil any orders. The company is also writing to all customers from the past 12 months to let them know about the incident, though it said it did not believe account passwords had been compromised.
"As soon as we discovered the incident last Thursday, we launched a forensic investigation led by external experts to understand the incident and whether there has been any impact on customer data," Funky Pigeon said in a statement.
"We are currently investigating the extent to which any personal data - specifically names, addresses, email addresses and personalised card and gift designs - has been accessed. We take the security of customer data extremely seriously and we have temporarily suspended any new orders via the website."
The attack has come just a couple of weeks after a similar incident suffered by The Works, which was also forced to shut down some parts of its operation.
When an organisation is breached by a cyber attack, its security teams are under immense pressure to get their services back up and running as soon as possible, according to Justin Vaughan-Brown, VP of strategic communications at Deep Instinct.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"On top of this stress, security teams have the constant fear of threat actors returning to the network to cause further harm, with a second attack potentially causing lasting and irreversible damage," Vaughan-Brown said. "Organisations must, therefore, invest in security solutions that are proactive and preventative, rather than reactive, to ensure that cyber attacks are stopped before they damage an organisation's network. "
Bobby Hellard is ITPro's Reviews Editor and has worked on CloudPro and ChannelPro since 2018. In his time at ITPro, Bobby has covered stories for all the major technology companies, such as Apple, Microsoft, Amazon and Facebook, and regularly attends industry-leading events such as AWS Re:Invent and Google Cloud Next.
Bobby mainly covers hardware reviews, but you will also recognize him as the face of many of our video reviews of laptops and smartphones.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard Published
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd Published
-
ICO admits it's too slow dealing with complaints – so it's eying up automation to cut staff workloads
News The UK's data protection authority has apologized for being slow to respond to data protection complaints, saying it's been overwhelmed by increased workloads.
By Emma Woollacott Published
-
“Limited resources” scupper ICO probe into EasyJet breach
News The decision to drop the probe has been described as “deeply concerning” by security practitioners
By Ross Kelly Published
-
Surge in workplace monitoring prompts new ICO guidelines on employee privacy
News Detailed guidance on how to implement workplace monitoring could prevent data protection blunders
By Ross Kelly Published
-
TikTok could be hit with £27m fine for failing to protect children's privacy
News Social media firm issued with a notice from the ICO for potential violations of UK data protection laws
By Bobby Hellard Published
-
What is AdTech and why is it at the heart of a regulation storm?
In-depth The UK data regulator has come under heavy fire for consistently delaying much-needed action, privacy groups say
By Carly Page Published
-
ICO crackdown on AI recruitment part of three-year vision to save businesses £100 million
News ICO25 outlines a fresh approach that involves releasing learning materials, advice, and a new ICO-moderated discussion forum for businesses
By Connor Jones Published
-
Clearview AI fined £7.5m over improper use of UK data
News Australian facial recognition firm collected 20 billion images from the internet without consent in order to build its database
By Bobby Hellard Published
-
UK data watchdog cut IT spending by £1.2 million during pandemic
News The ICO’s IT budget has been slashed by around 23% since 2019
By Sabina Weston Published