CTIPilot

LPG Group

actor · actor:lpg-group

Previously undocumented extortion actor that breached an internal Order Hub ordering system at grocery-delivery service Flink and, after Flink refused a corporate Ethereum ransom, pivoted to directly extorting at least 10,000 individual customers and employees in a collective-threshold 'crowdfunding' scheme (heise online / NL Times, 2026-09-25/26).

Coverage timeline
1
first 2026-09-27 → last 2026-09-27
Peak priority
notable
1 notable
Sources cited
2
2 hosts
Sections touched
1
active-threats
Co-occurring entities
1
see Co-occurring entities below
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques

ATT&CK techniques

1 technique observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Impact TA0040

T1657Financial Theft×1

Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.

Evidence: 2026-09-27/flink-lpg-group-crowdfund-extortion-order-hub-breach · ATT&CK page ↗

Story timeline

  1. 2026-09-27Flink refuses a corporate ransom after an Order Hub breach, so extortion actor "LPG Group" pivots to crowdfund-style individual extortion of at least 10,000 customers and employees
    active-threatsA refused corporate ransom becomes 10,000+ individual shakedown emails: an extortion playbook worth recognizing before it recurs

Where this entity is cited

  • active-threats1

Source distribution

  • heise.de1 (50%)
  • nltimes.nl1 (50%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about LPG Group (1)

2026-09-27 · view entry permalink →

NOTABLENATOB1

Flink, a quick-commerce grocery delivery service headquartered in Germany and also operating in the Netherlands (formerly in Austria and France), confirmed a breach of one of its internal "Order Hub" ordering systems, the decentralized, city-level warehouse software that lets the service promise delivery in under thirty minutes (heise online, 2026-09-26). The company has not disclosed the initial-access vector; it says the specific Order Hub instance involved has been identified and unauthorized access to it cut off. Attackers first approached Flink directly, demanding payment in the cryptocurrency ETH and promising to delete the data if paid. Flink states plainly that it does not negotiate with criminals and did not respond (heise online, 2026-09-26).

The extortion actor behind the breach, self-named "LPG Group" and previously undocumented, claims to have obtained personal information on a million Flink customers and 13,000 workers; Flink has not confirmed that figure, though NL Times notes one million would represent roughly two-thirds of the customer base the company reported in June (NL Times, 2026-09-25). Rather than walk away after Flink's refusal to pay a corporate ransom, the group pivoted to mass-emailing individuals directly. At least 10,000 customers and employees in the Netherlands received ransom notes (heise reports Germany was also targeted, though the scale there is unclear), each demanding a small payment of 0.005 ETH (NL Times: the equivalent of EUR 11.80) toward a collective target of 100 ETH, which NL Times puts at just shy of EUR 237,300 and heise at roughly EUR 230,000, a discrepancy the two outlets' independent exchange-rate snapshots do not resolve, with a promise to delete each payer's data once the collective goal is met and a threat to sell everything if it is not, by a 2 October 2026 deadline (NL Times, 2026-09-25; heise online, 2026-09-26). The emails address recipients by name from a spoofed, Flink-resembling sender, which the outlets note makes them more convincing than a generic mass-phishing blast. Exfiltrated data is limited to names, postal codes/delivery addresses, email addresses, phone numbers and, in some cases, delivery notes such as floor or apartment details; Flink states passwords, payment card details and bank data were not affected (NL Times, 2026-09-25; heise online, 2026-09-26).

Cybersecurity researcher Pim Takkenberg of Northwave called the crowdfunding-style extortion attempt exceptional, noting that ShinyHunters had previously extorted Dutch higher-education institutions that were clients of a hacked software system. "But I haven't seen individual consumers being approached before," Takkenberg told Dutch broadcaster NOS (Pim Takkenberg, Northwave, via NL Times, 2026-09-25). Abuse reporting to the group's mail provider curtailed the flood of messages, and only around 150 customers had proactively contacted Flink's support line as of reporting, leaving the true scale of contacted individuals, particularly in Germany, unclear. Flink has notified Berlin's data protection authority and police in both Germany and the Netherlands, and retained external IT forensics; heise's own coverage notes the company has not, contrary to an earlier report, engaged Germany's BSI (heise online, 2026-09-26).

If not, the data would, literally, be "sold on the deep web." The extortionists have thus turned to a kind of criminal crowdfunding against a company unwilling to pay. (translated from German)

heise online 2026-09-26

But I haven't seen individual consumers being approached before

Pim Takkenberg, Northwave, via NL Times

As a matter of principle, Flink does not make contact with criminals and does not conduct negotiations with them. (translated from German)

Flink, quoted by heise online
incident27 Sep 04:32Zmulti-sourceOpen finding ↗