Pandora emailed customers on 5 August 2025 that "your contact information was accessed by an unauthorized party through a third-party platform we use", and that it had stopped the access. Pandora told customers the data was names and email addresses, with no passwords or card details. Forbes, as cited by BleepingComputer, reported that birth dates were taken too. Pandora did not name the platform. BleepingComputer reported that the data was taken from Pandora's Salesforce database, in the same wave of thefts from companies' Salesforce accounts that hit Chanel.
Customer contact details taken through an outside platform it uses
affected · A third-party platform Pandora uses to hold customer data
- If you'd stopped using them
- A deletion request, sent when you left, asks them to delete what they hold. If they had, less of yours would have been in what was taken.
- If you still used them
- A limit request asks them to stop using your data for marketing, for sharing with partners, and for research or profiling.
Their reply would have been their claim, dated, and yours to point to now.
More events
The rest of the wire, newest first.
Notice 8 Oct 2026
Customer profiles with addresses and site searches taken through a phished staff login
ASOS emailed customers on 8 October 2026 that someone "impersonating a trusted contact" got an employee's login and used it "to access information on certain third-party platforms used by Asos". A sample the attackers sent to BBC News holds names, addresses, phone numbers, emails, customer numbers and searches made on the site. Searches next to a name and an email are a record of what someone was looking at, including things they might never tell anyone. The attackers claimed to the BBC they got in through Simon AI, a marketing data platform. ASOS has named no platform; Simon AI's website lists ASOS as a customer. ASOS has given no numbers.
Notice · Retail
Incident 6 Oct 2026
Attackers sent a push alert through its own app, threatening to leak its data
At about 10am on 6 October 2026, ASOS customers received a push notification through its app from attackers who said they had "fully compromised the Snowflake instance" and threatened to leak it. ASOS told the London Stock Exchange that day it was investigating unauthorised activity on "third-party platforms that we use to communicate with customers" and that "basic personal information including name and contact details may have been accessed". It said it did not believe payment card details or passwords were affected. Snowflake said its own platform had not been breached. The UK's National Cyber Security Centre tells every ASOS customer to assume they are affected, even without the notification.
Incident · Retail
Notice 29 Sept 2026
Buyers of business opportunity programmes at seminars offered for rent as a list
A mailing list called Millennium Business Opportunity Buyers, managed by Geon Media, is offered for rent on the NextMark list directory. Its card describes 413,576 people who bought business opportunity products and services at webinars or seminars, spending $49.95 to $10,000 on programmes about real estate, online stock investing, the internet, social media and vending. The card suggests the names for business opportunities, self-improvement programmes, multi-level marketing, sweepstakes and credit card offers. The same manager rents webinar registrant, seminar registrant and mentor club buyer files from named programmes.
Notice · Advertising & Marketing