News

Flink Was Breached And Now Hackers Are Emailing Its Customers for Ransom Too

Flink data breach LPG Group

LPG Group breached Flink using compromised employee login credentials and accessed an internal system containing names, email addresses, home addresses, phone numbers, and, for some customers, detailed delivery instructions. The group claims over one million customers and 13,000 employees are affected. They demanded 100 ETH (approximately €238,000) from Flink and separately emailed customers demanding 0.005 ETH (approximately €10) each, threatening dark web sale of personal data by October 2. Flink has confirmed the breach and told customers not to pay.

Most ransomware attacks follow a predictable arc. Attackers get in, steal data, lock systems, demand payment from the company, threaten to publish. The company negotiates or refuses. Customers hear about it weeks later in a breach notification email.

LPG Group, a ransomware extortion operation that apparently launched its first campaign this very month, has decided that model doesn’t capture enough revenue.

They breached Flink, the European quick-commerce grocery delivery service. They demanded €238,000 from the company. And then they emailed Flink’s customers directly, over a million of them, asking each person for €10 to keep their personal data off the dark web by October 2.

The tactic has a name: triple extortion. But LPG Group added something the existing triple extortion playbook doesn’t typically include, and that detail is what makes this case worth understanding.

Who LPG Group Is – And Why a Brand-New Group Matters

The Cybernews reporting makes one small observation that deserves much more weight: LPG Group “started its extortion practices just this month.”

This is their debut. Or if it isn’t, September 2026 is the first time anyone has publicly documented them.

That makes the Flink breach a proof-of-concept campaign. A new group choosing a consumer-facing quick-commerce platform as its first publicly named victim, and immediately deploying a novel three-vector extortion strategy, suggests either significant pre-existing capability or a deliberate choice to come out of the gate with something that would generate press attention and demonstrate the model to potential future targets and affiliates.

The “debut operation” pattern has appeared before in criminal ecosystems. As we covered in the AudiA6 crypto laundering takedown and the SilentRansomGroup’s sustained law firm campaign, newly operational groups often select their first targets to maximize visibility and establish credibility. A million-customer consumer brand delivers both.

How They Got In

According to German trade magazine Retail News, which has reviewed the breach details, LPG Group accessed Flink’s internal systems using compromised login credentials from one of the company’s employees.

This is the same entry point that enabled numerous major 2026 breaches. An employee credential, obtained through phishing, infostealer malware, or purchase from a dark web credential market, gets the attacker inside an authenticated session on internal infrastructure. Once inside, lateral movement and data exfiltration follow.

Flink confirmed the breach and said it immediately initiated what it described as “comprehensive countermeasures” and brought in external IT forensics and cybersecurity experts to determine the scope. The unauthorized access has been stopped. The investigation is ongoing.

What Was Actually Taken

The data in the breach covers the full profile of a food delivery customer.

Names, email addresses, home addresses, and phone numbers were exposed. For a subset of customers, the breach extends to delivery-specific details: the floor number of their apartment, the name on their doorbell, and any delivery instructions they had on file.

That last category sounds mundane. It isn’t. A home address tells someone where you live. An address combined with a floor number, your name as it appears on a doorbell, and explicit instructions like “leave by back gate if no answer” tells someone exactly how to find you, when you’re likely in or out, and how to approach your home without raising suspicion.

This is the same concern researchers raised about the 153 million driver’s license exposures through IDScan.net, which address that exposure isn’t just an identity theft risk. For a non-trivial number of people, particularly anyone with safety concerns about their home location, it’s a physical security risk. Delivery services accumulate unusually precise location data, and this breach put that data in criminal hands.

According to Flink’s notification, passwords were not exposed. That’s a meaningful limitation on what attackers can do with this data directly, but it doesn’t reduce the risk from targeted phishing, smishing, or physical approaches.

The €10 Email: Triple Extortion With a Twist

This is the piece that makes the Flink case genuinely new, and it deserves a careful read.

LPG Group has already demanded 100 Ethereum, approximately €238,000, from Flink itself, threatening to release the stolen data if the company doesn’t pay. That’s standard double extortion.

They’ve then separately emailed Flink’s customers directly with this message: “If you refuse to pay 0.005 ETH (about €10) by October 2, your personal information will be sold on the dark web.”

That’s triple extortion, targeting both the company and the individuals whose data was taken.

But the last sentence of that customer email adds the twist: “You can forward this email to Flink to get their attention.”

This turns Flink’s own customers into a lobbying force. One million people who each receive an email telling them to pressure Flink to pay up creates a volume of customer contact and reputational pressure that no PR team is prepared to manage. It’s extortion that weaponizes victims against the breached organization — a mechanism that conventional double extortion simply doesn’t have.

The €10 price point isn’t accidental either. It’s small enough that some people will pay it without thinking twice; the cognitive cost of disputing €10 is often higher than just paying it. But across a million customers, €10 each represents up to €10 million. And each payment also proves the model works, generating intelligence for future campaigns.

Why Paying Is Still the Wrong Choice

Flink’s own customer notification is direct: be cautious with unexpected emails, messages, or calls referencing Flink; do not reply, and do not make any payments.

This advice is correct for several reasons.

Paying gives LPG Group no reason to delete your data. The same research showing that removed data doesn’t actually disappear applies directly here. A criminal group that receives payment from enough customers has already demonstrated a successful model. The data gets sold anyway, or held for future leverage, or shared with other criminal networks.

More practically: paying is proof of engagement. A customer who pays €10 has confirmed that they received the email, the address is live, they responded to pressure, and they’re willing to make small cryptocurrency transactions. That’s a profile worth more than €10 to future fraud campaigns.

Flink’s guidance not to pay is the right call. Forward the email to Flink’s security or data protection contacts for documentation, as they’re presumably logging all incoming reports from affected customers to understand the campaign’s scope.

What Flink Customers Should Do Right Now

Since your delivery address, phone number, and, for some customers, your exact apartment layout details may now be in LPG Group’s hands, the practical steps go beyond “don’t click phishing links.”

Watch for any delivery-related communications you didn’t initiate, calls claiming to be from Flink support, text messages about supposed failed deliveries, or emails asking you to update payment methods or confirm your address. These are the specific social engineering vectors your data now enables.

If you’ve used the same password for Flink as for other services, change them. Passwords weren’t in this breach, but credential reuse remains the main reason one breach becomes five.

For a complete checklist on what to do when personal data is in criminal hands, our guide to responding when your data appears on the dark web covers the steps in the right order.

Reporting the extortion email to your national data protection authority is also appropriate. GDPR breach notification obligations apply here, and several EU member states have dedicated reporting channels for exactly this kind of direct-to-consumer extortion.

Frequently Asked Questions

What is Flink?

A European quick-commerce grocery delivery service, operating primarily in Germany and other European markets.

What data was exposed?

Names, email addresses, home addresses, phone numbers, and for some customers, delivery-specific details including floor numbers, doorbell names, and delivery instructions.

Who is LPG Group?

A newly identified ransomware extortion group that appears to have begun operations in September 2026. The Flink breach is their first publicly documented attack.

What is triple extortion?

A tactic in which ransomware groups extort both the breached company and the affected individuals separately. LPG Group extended this by telling victims to forward the ransom demand to Flink, turning customers into pressure agents against the company.

Should I pay the €10?

No. Flink has explicitly told customers not to pay. Payment does not guarantee your data is deleted, confirms your details are active, and demonstrates you’ll respond to criminal pressure.

What is the deadline?

October 2, 2026, according to LPG Group’s email to customers.

Muhammad Anas

Written by Muhammad Anas

Contributing writer at DarkWebDecoded.com covering dark web security, scam alerts, and privacy tools.

📋 Latest Articles

View all →
Fujitsu and KELA Are Bringing Dark Web Intelligence to Japan's Corporate Security Front Line
News

Fujitsu and KELA Are Bringing Dark Web Intelligence to Japan’s Corporate Security Front Line

Fujitsu Limited launched a three-component cybersecurity service on September 25, 2026, combining dark web monitoring, attack surface management,…

Sep 25, 2026
6 min read
Project Ghostwire dark web bust
News

Project Ghostwire: The Dark Web Drug Ring That Kept 50,000 Fatal Doses of Fentanyl in Stock

Project Ghostwire dismantled Icy White North, described by York Regional Police as one of Canada’s most prolific dark…

Sep 24, 2026
7 min read
Is your Social Security number on the dark web?
Monitoring

Is Your Social Security Number on the Dark Web?

If you just got an alert saying your Social Security number showed up on the dark web, take…

Sep 22, 2026
6 min read
ShinyHunters hacks cl0p ransomware
News

ShinyHunters Didn’t Just Deface Cl0p’s Site. They Took the Keys to It.

ShinyHunters breached cl0p’s dark web leak site on September 19, 2026, by exploiting an unauthenticated file upload vulnerability…

Sep 21, 2026
6 min read
How to Use Ahmia Search Engine
Guides

How to Use Ahmia Search Engine: A Safe, Step-by-Step Guide

Most search engines can’t see the Tor network at all. Google doesn’t index .onion sites, and neither does…

Sep 21, 2026
7 min read
ShinyHunters Just Hijacked Cl0p's Dark Web Site
News

ShinyHunters Just Hijacked Cl0p’s Dark Web Site. Here’s the Beef Behind It.

When criminals fall out, they don’t call lawyers. They go after each other’s infrastructure. On September 19, 2026,…

Sep 21, 2026
4 min read
0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted