Flink Data Breach: No One Paid Hackers’ €10 to €15 Demands
Nobody paid hackers' €10 to €15 demands after the Flink data breach. Digital rights advocates warn that exposed contact details still pose risks, especially for vulnerable people.
Hackers sought more than €200,000, but digital rights advocates warn that breach fatigue can hide serious risks.
Customers in the Netherlands faced €10 to €15 payment demands after the flink data breach last week, which targeted grocery delivery service Flink. The hackers threatened to publish stolen customer information on the dark web unless customers paid in cryptocurrency.
However, nobody paid the demanded amount. The hackers had hoped to collect more than €200,000. Their failed collection attempt sits alongside a wider concern: repeated breaches may leave people less willing to react.
The case appears in original reporting by NOS, the Dutch public broadcaster. Experts described declining public concern about repeated leaks of personal information. Yet digital rights advocates warned that a muted response does not mean the information poses no danger.
Small demands, potentially serious harm
The hackers asked individual customers for relatively small sums. However, their overall target exceeded €200,000. They used the threat of publication to pressure people into paying.
Bits of Freedom, a Dutch digital rights organisation, warned against dismissing the consequences. Its spokesperson, Rejo Zenger, said: “Het is veel te gemakzuchtig dat we hier onze schouders over ophalen.” He warned that shrugging off the risks was far too complacent.
In particular, he pointed to people experiencing domestic violence. Exposed email addresses or phone numbers can have serious consequences for them.
Why repeated breaches can feel routine
Experts described a growing sense of data breach fatigue. Frequent reports of stolen information can make each new incident feel familiar. As a result, some people may feel less urgency when another company reports a hack.
Likewise, the absence of payments tells us only that the collection attempt failed. It does not confirm that the hackers deleted the information. Customers should therefore separate the payment outcome from the question of their personal exposure.
What this means for people living in the Netherlands
Customers should check which personal details were exposed if they receive a breach notification, cybersecurity expert Paul Pols told NOS.
Experts advised customers not to send cryptocurrency in response to an extortion demand. Payment offers no reliable guarantee that criminals will delete stolen information.
What customers should watch for next
The central distinction is simple: nobody paying does not make exposed personal information harmless.