a Samsung sign on a storefront in London
Image Credits:Future Publishing / Contributor / Getty Images
Security

Samsung says hackers accessed customer data during year-long breach

Samsung has admitted that hackers accessed the personal data of U.K.-based customers during a year-long breach of its systems.

In a statement to TechCrunch, Samsung spokesperson Chelsea Simpson, representing the company via a third-party agency, said Samsung was “recently alerted to a security incident” that “resulted in certain contact information of some Samsung U.K. e-store customers being unlawfully obtained.”

Samsung declined to answer further questions about the incident, such as how many customers were affected or how hackers accessed its internal systems.

In a letter sent to affected customers, Samsung admitted that attackers exploited a vulnerability in an unnamed third-party business application to access the personal information of customers who made purchases at Samsung U.K.’s store between July 1, 2019 and June 30, 2020.

In the letter, which was shared on X (formerly Twitter), Samsung said it didn’t discover the compromise until more than three years later, on November 13, 2023.

Samsung told affected customers that hackers may have accessed their names, phone numbers, postal addresses and email addresses. “No financial data, such as bank or credit card details or customer passwords, were impacted,” Samsung’s spokesperson told TechCrunch, adding that the company had reported the issue to the U.K.’s Information Commissioner’s Office (ICO).

ICO spokesperson Adele Burns confirmed to TechCrunch that the U.K. data protection regulator is aware of the incident and “will be making enquiries.”

Techcrunch event

Join 10k+ tech and VC leaders for growth and connections at Disrupt 2025

Netflix, Box, a16z, ElevenLabs, Wayve, Hugging Face, Elad Gil, Vinod Khosla — just some of the 250+ heavy hitters leading 200+ sessions designed to deliver the insights that fuel startup growth and sharpen your edge. Don’t miss the 20th anniversary of TechCrunch, and a chance to learn from the top voices in tech. Grab your ticket before doors open to save up to $444.

Join 10k+ tech and VC leaders for growth and connections at Disrupt 2025

Netflix, Box, a16z, ElevenLabs, Wayve, Hugging Face, Elad Gil, Vinod Khosla — just some of the 250+ heavy hitters leading 200+ sessions designed to deliver the insights that fuel startup growth and sharpen your edge. Don’t miss a chance to learn from the top voices in tech. Grab your ticket before doors open to save up to $444.

San Francisco | October 27-29, 2025

This incident is the third data breach that Samsung has disclosed in the past two years.

In September 2022, the company confirmed in a brief notice that attackers had accessed some information from some of Samsung’s U.S. systems but declined to say how many customers were affected. Prior to this, in March 2022, Samsung confirmed that it had suffered a breach after Lapsus$ hackers claimed to have obtained and leaked almost 200 gigabytes of confidential data from the company’s systems, including source code for various technologies and algorithms for biometric unlock operations.

Parsing Samsung’s data breach notice

Topics

, , ,
Loading the next article
Error loading the next article