Samsung has informed its UK customers of a security breach that has affected the company's systems for nearly a year. Criminals were able to access customers' personal data, but Samsung did not provide further details beyond this statement.
The data of UK customers who purchased Samsung devices through the company's official e-commerce store between July 1, 2019 and June 30, 2020, was leaked by an "unauthorized individual." Samsung discovered the vulnerability on November 13, 2023, confirming that unknown hackers were able to access its systems by exploiting security holes in third-party business applications used by the company.
Samsung said in an email that hackers obtained "some" personal information of an unspecified number of users over a year. According to the company's own investigation, the compromised data "may" include customers' names, phone numbers, home addresses and email addresses. The South Korean company said "financial" information such as passwords or bank or credit card details were not affected.
Samsung confirmed that the new cybersecurity incident is limited to the UK region, while customers, employees, retailers and other parties in the US and elsewhere around the world should be safe this time around. Shortly after the vulnerability was discovered, Samsung reported the incident to the UK Information Commissioner's Office.
An ICO spokesperson confirmed that the consumer electronics giant had reported the issue to the UK data protection agency and that ICO investigators were currently "conducting an investigation". Neither Samsung Electronics representatives nor the ICO provided further details about the data breach that may have affected a large number of UK citizens.
Samsung's recent history of security breaches is concerning, as this is the third major incident the company has suffered in the past few years. In September 2022, the South Korean company said hackers were able to access some information on its U.S. systems.
A third incident affected the company in March 2022, when Lapsus$ hackers leaked nearly 200GB of confidential data obtained from Samsung servers. The vast amount of data includes source code for various technical components of Galaxy smartphones, algorithms for biometric unlocking methods, and more. Samsung confirmed that "certain internal data" had been "stolen" by unauthorized parties.