UK Retailer Confirms Data Breach Affecting 8 Million Customer Records
A major UK retailer has confirmed a data breach exposing approximately 8 million customer records over a 6-week period, including encrypted payment card data. The company carries cyber insurance and has engaged forensic investigators, while the ICO has opened a formal investigation. The retailer faces potential GDPR fines of up to 4% of global annual turnover, creating a meaningful cyber liability exposure.
AI-generated from linked source reports. See our correction policy.
Impact verdict
Medium impact. MEDIUM: A confirmed cyber data breach affecting 8 million records at an insured UK retailer will activate cyber insurance coverage for forensic costs, notification expenses, credit monitoring, and potential regulatory fines. GDPR fines at 4% of global turnover for a major retailer could be material. The ICO investigation adds regulatory liability exposure relevant to cyber and casualty books. Loss quantum is unclear pending investigation outcome, but the insured loss is confirmed and plausible across multiple cyber policy towers.
View assessment methodologyPremium discovery tier
Unlock analyst briefs, intelligence depth, and the revision timeline
Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.
Start two-week trialAffected countries
Lloyd's classifications
Tracking this kind of risk? Get an email when Cyber events escalate.
Get alerts