A New Twist in the Flink Data Breach
The fallout from the Flink data breach has taken an unusual turn. According to reporting on the incident, the extortion group behind the attack, known as LPG Group, is no longer just pressuring the grocery delivery company for a payout. Cybercriminals are now sending ransom notes directly to individual customers and employees whose personal information was allegedly stolen.
As previously reported, LPG Group claimed to have exfiltrated data belonging to more than one million Flink shoppers and roughly 13,000 employees. That earlier demand targeted Flink itself, with the group reportedly asking for 100 ETH, worth around €237,300 at the time, in exchange for not leaking the stolen records. Flink's internal systems were confirmed as the affected environment, and the investigation into the breach remains ongoing.
What makes this latest development notable is the shift in tactics. Rather than relying solely on pressuring the company, the attackers are reportedly contacting individuals directly, demanding a much smaller sum: €11.80, or the equivalent of 0.005 ETH, from each person whose data appears in the stolen dataset. The implication is that paying the small fee might keep that person's specific information out of any public leak, while nonpayment could mean their data gets published alongside everyone else's.
Why Targeting Individuals Changes the Equation
This approach, sometimes called multi-tiered or triple extortion, is a departure from the more familiar playbook where a ransomware or extortion group negotiates exclusively with the breached organization. By reaching out to customers and workers separately, attackers create a second revenue stream and add psychological pressure that a corporate negotiation alone doesn't generate.
For the people receiving these notes, the demand is deliberately small. A payment of €11.80 is easy to dismiss as trivial, which is likely the point. Extortionists count on victims deciding it's simpler to pay a small amount than to deal with the uncertainty of having personal data exposed. But security professionals generally advise against paying these kinds of demands. There is no guarantee that payment actually removes a person's data from wherever it has already been copied or sold, and paying can mark someone as a soft target for future extortion attempts.
The data reportedly stolen in the Flink breach includes information tied to both customers and employees, meaning the exposure could touch people who never interacted with the company as a shopper at all. That breadth is part of why this incident has drawn attention beyond the usual cybersecurity circles: it illustrates how a single corporate breach can generate direct consequences for thousands of individuals who had no say in how their employer or the service they used secured their data.
What This Means For You
If you have ever placed an order with Flink or worked for the company, it is worth treating any unexpected message referencing a data breach with caution. Legitimate breach notifications from Flink would come through official channels, not as a payment demand tied to cryptocurrency. Messages asking for a small fee in exchange for keeping your data private are a hallmark of extortion, not a legitimate remediation process.
Do not click on links or send payment based on an unsolicited message claiming to hold your data hostage. Instead, verify any breach claims through Flink's own communications or trusted news coverage, and consider the security basics that apply after any breach: changing reused passwords, enabling multi-factor authentication where available, and monitoring your accounts and email for signs of phishing that might reference details from the leaked data to appear more convincing.
It's also worth remembering that the investigation into this incident is still active. Details about the scope of the data, which specific fields were exposed, and how Flink plans to respond may continue to evolve. Keeping an eye on updates rather than reacting immediately to a ransom note is generally the safer path.
Staying Ahead of Extortion Tactics
The Flink data breach is a reminder that the aftermath of a corporate hack doesn't always stay contained to boardroom negotiations. When attackers exfiltrate large volumes of personal data, individuals can become direct targets of extortion attempts long after the initial breach headline fades.
A few practical steps can help limit the damage. Avoid engaging with or paying unsolicited ransom demands, even small ones, since payment offers no real assurance and may invite further targeting. Report suspicious messages to the company involved and to relevant consumer protection or cybercrime authorities. And treat any breach as an opportunity to review your broader digital hygiene, including password reuse and account monitoring, since stolen data from one incident often resurfaces in unrelated phishing campaigns later.
As this story develops, staying informed through verified reporting rather than reacting to unsolicited messages remains the best defense against becoming a secondary victim of the Flink breach.




