CTIPilot
← Back to the live brief
NOTABLENATOB1incident

Flink refuses a corporate ransom after an Order Hub breach, so extortion actor "LPG Group" pivots to crowdfund-style individual extortion of at least 10,000 customers and employees

A refused corporate ransom becomes 10,000+ individual shakedown emails: an extortion playbook worth recognizing before it recurs

Analysis

Flink, a quick-commerce grocery delivery service headquartered in Germany and also operating in the Netherlands (formerly in Austria and France), confirmed a breach of one of its internal "Order Hub" ordering systems, the decentralized, city-level warehouse software that lets the service promise delivery in under thirty minutes (heise online, 2026-09-26). The company has not disclosed the initial-access vector; it says the specific Order Hub instance involved has been identified and unauthorized access to it cut off. Attackers first approached Flink directly, demanding payment in the cryptocurrency ETH and promising to delete the data if paid. Flink states plainly that it does not negotiate with criminals and did not respond (heise online, 2026-09-26).

The extortion actor behind the breach, self-named "LPG Group" and previously undocumented, claims to have obtained personal information on a million Flink customers and 13,000 workers; Flink has not confirmed that figure, though NL Times notes one million would represent roughly two-thirds of the customer base the company reported in June (NL Times, 2026-09-25). Rather than walk away after Flink's refusal to pay a corporate ransom, the group pivoted to mass-emailing individuals directly. At least 10,000 customers and employees in the Netherlands received ransom notes (heise reports Germany was also targeted, though the scale there is unclear), each demanding a small payment of 0.005 ETH (NL Times: the equivalent of EUR 11.80) toward a collective target of 100 ETH, which NL Times puts at just shy of EUR 237,300 and heise at roughly EUR 230,000, a discrepancy the two outlets' independent exchange-rate snapshots do not resolve, with a promise to delete each payer's data once the collective goal is met and a threat to sell everything if it is not, by a 2 October 2026 deadline (NL Times, 2026-09-25; heise online, 2026-09-26). The emails address recipients by name from a spoofed, Flink-resembling sender, which the outlets note makes them more convincing than a generic mass-phishing blast. Exfiltrated data is limited to names, postal codes/delivery addresses, email addresses, phone numbers and, in some cases, delivery notes such as floor or apartment details; Flink states passwords, payment card details and bank data were not affected (NL Times, 2026-09-25; heise online, 2026-09-26).

Cybersecurity researcher Pim Takkenberg of Northwave called the crowdfunding-style extortion attempt exceptional, noting that ShinyHunters had previously extorted Dutch higher-education institutions that were clients of a hacked software system. "But I haven't seen individual consumers being approached before," Takkenberg told Dutch broadcaster NOS (Pim Takkenberg, Northwave, via NL Times, 2026-09-25). Abuse reporting to the group's mail provider curtailed the flood of messages, and only around 150 customers had proactively contacted Flink's support line as of reporting, leaving the true scale of contacted individuals, particularly in Germany, unclear. Flink has notified Berlin's data protection authority and police in both Germany and the Netherlands, and retained external IT forensics; heise's own coverage notes the company has not, contrary to an earlier report, engaged Germany's BSI (heise online, 2026-09-26).

Cited evidence

If not, the data would, literally, be "sold on the deep web." The extortionists have thus turned to a kind of criminal crowdfunding against a company unwilling to pay. (translated from German)

heise online 2026-09-26

But I haven't seen individual consumers being approached before

Pim Takkenberg, Northwave, via NL Times

As a matter of principle, Flink does not make contact with criminals and does not conduct negotiations with them. (translated from German)

Flink, quoted by heise online

Sources2

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.