← Blog

IKEA Data Breaches: Full Timeline Through 2026

Share on X

People search IKEA data breach timeline because the brand sits on billions of accounts, credentials, and cloud workloads. BreachHistory indexes 3 IKEA-linked incidents, with headline counts up to 95K+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.

Why IKEA breach history matters

IKEA operates in Technology (India). Across indexed rows, recurring themes include ransomware and extortion, cloud and database misconfiguration, unverified actor or scraping claims. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.

Full timeline through 2026

2026 — Lapsus$ claim of 180GB internal source code (June 2)

Unverified claim — treat actor counts cautiously. On June 2, 2026, Cybernews reported that Lapsus$ claimed to be selling roughly 180 gigabytes of internal data from Ingka Group—the largest IKEA franchisee—including alleged source-code repositories, e-commerce architecture maps, supply-chain logistics systems, cloud infrastructure, and AI/MLOps repos. A sample directory tree referenced about 6,300 internal tool paths without verified file contents. IKEA had not officially confirmed a breach at catalog time; BreachHistory tracks source-code exposure risk separate fr Exposed categories include Alleged internal source code, architecture maps, and infrastructure metadata—not confirmed customer records. No attested victim count is published for this row yet. See the ikea-ingka-lapsus 2026 record and canonical BreachHistory entry.

2022 — employee search exposure, 95K customers

Cataloged incident. Employee performed generic search on customer database (Mar 1–3); customer data exposed in results. Names, emails, phone numbers, postal codes, IKEA Family numbers. No financial data. Privacy Commissioner notified. Exposed categories include Names, emails, phone numbers, postal codes, loyalty numbers. BreachHistory cites approximately 95K+ affected records in this row. See the ikea-canada2022 and canonical BreachHistory entry.

2022 — 95k customers

Cataloged incident. IKEA Canada confirmed a data breach involving personal information of approximately 95,000 customers. The breach was discovered during a routine security review. Exposed categories include Names, addresses, phone numbers, order history. BreachHistory cites approximately 95K+ affected records in this row. See the ikea2022 and canonical BreachHistory entry.

Patterns and analysis

  • Ransomware and extortion — appears across multiple IKEA catalog entries; prioritize controls that address this class of failure.
  • Cloud and database misconfiguration — appears across multiple IKEA catalog entries; prioritize controls that address this class of failure.
  • Unverified actor or scraping claims — appears across multiple IKEA catalog entries; prioritize controls that address this class of failure.
  • Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
  • 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.

What to do if you may be affected

  1. Step 1: Enable phishing-resistant MFA on every account tied to this brand.
  2. Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
  3. Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
  4. Step 4: Review OAuth app permissions and revoke unused third-party integrations.
  5. Step 5: Bookmark the IKEA company page for new 2026+ disclosures.

Canonical BreachHistory hub

Explore every indexed row: breachhistory.com/ikea · Latest: ikea-ingka-lapsus2026.

Sources: BreachHistory catalog (3 rows for IKEA), company and regulator disclosures cited in individual breach records.