Skroutz Last Mile told customers on 23 September 2026 that attackers got unauthorized access to an IT system that stores parcel shipment data. Full names, delivery addresses, and contact telephone numbers were in that system. Credit cards, other payment data, and credentials were not — the courier says those fields are not stored on the affected systems at all.
If you ordered through Greece’s Skroutz marketplace and a Last Mile courier or Skroutz Point locker handled the package, treat this as a confirmed Skroutz Last Mile data breach on shipment contact fields. Canonical record: skroutz-last-mile2026.
What happened in the Skroutz Last Mile data breach
The courier arm of Greek e-commerce platform Skroutz sent a customer notice on Wednesday, 23 September 2026. English coverage from ProtoThema and eKathimerini quotes the same core facts: unauthorized access to a company information system where parcel shipment data are stored; exposed categories limited to full name, address, and contact telephone number; immediate containment; cooperation with supervisory authorities; and a phishing warning.
The company has not published a headcount. Do not invent one. “Some customers” is as far as the English trade press goes. Last Mile’s share of Skroutz orders — 70% in 2025, up from 52% in 2024, per eKathimerini — tells you the delivery network is large, not how many rows sat in the hit system.
What this is not: a claim that every Skroutz account password leaked, that card vaults were emptied, or that a ransomware group posted a Greek dump with a verified census. The primary story is a courier logistics database of who gets what parcel where, and how to call them.
What data was exposed — and what was not
Affected, per Skroutz Last Mile’s customer message:
- Full name
- Address
- Contact telephone number
Not affected, per the company, because these are not stored on Skroutz Last Mile systems tied to the incident:
- Credit card numbers
- Other payment information
- Credentials / passwords
That split matters. A courier system needs a name on the label, a street for the driver, and a phone for “we’re outside.” It does not need the card PAN you typed into Skroutz checkout. Payment and login secrets live elsewhere in the platform stack. Attackers who only got Last Mile shipment fields still have enough to forge convincing delivery SMS — they do not automatically have your Skroutz password or your Visa.
The notice does not say whether email addresses sat in the same tables. Stick to the three fields the company named. Assume phone and postal address are enough for doorstep and SMS fraud without inventing extra columns.
Why shipment PII still hurts
Greek parcel fraud does not need a CVV. It needs a name, a building door code conversation, and a phone that rings when a fake “redelivery fee” SMS lands. Last Mile also runs Skroutz Points — the orange lockers shoppers use to pick up and send parcels. A caller who already knows your name and street can claim a locker has been “held for ID verification” and walk you toward a phishing link.
Typical second-stage attacks after courier breaches:
- SMS: “Your Skroutz Last Mile package is waiting — confirm address / pay €2.90 storage”
- Viber or WhatsApp: “Driver cannot find your door — send photo of ID”
- Email with a PDF “customs clearance” form asking for IBAN or card
- Voice call that opens with your full name and street, then asks for a one-time code “to release the parcel”
None of those need your Skroutz password if the goal is a small payment or a SIM-swap pretext. The password-phishing variant will still appear: “Your Skroutz account was locked after the Last Mile incident — log in here.” The company’s own notice already told you credentials were not in the hit systems. A real Skroutz lockout will not start from a random link in SMS.
Timeline and what is still unknown
Public facts cluster on the notice date: 23 September 2026. Detection timing inside the company, dwell time, whether data was exfiltrated in bulk versus browsed, which host or VPN path failed, and the exact population of the shipment database are unpublished.
Open questions worth tracking without filling them in:
- Whether only active in-transit parcels were in scope or historical shipment records too
- Whether Skroutz Points locker pickups and merchant-to-consumer legs share the same system
- Whether Greek Data Protection Authority (HDPA) will publish a fine or reprimand later
- Whether a census appears in a later customer FAQ or regulator filing
Until a census exists, “was I affected?” is answered by behavior, not a magic lookup form. If Last Mile delivered your order, plan as if your name, address, and phone may now sit with someone who knows you buy through Skroutz. If you never used Skroutz, you can still receive copycat SMS that name the brand — ignore the lure, do not “check status” on links.
Who is at risk
Customers who received Last Mile deliveries. Home delivery and locker pickup both put your contact graph in courier systems. Recent orders are the obvious phishing targets; older addresses still work for long-game identity and doorstep social engineering.
People who share a household phone listed on a Skroutz order. The SMS hits the number on the label, not necessarily the person who clicked “buy.”
Merchants shipping via Skroutz Last Mile whose return or pickup contacts live in the same shipment store. The public notice is written to customers; merchant-side fields are not itemized. Do not invent them — do assume courier ops systems often hold sender phones too.
Not automatically every Greek shopper. Competing marketplaces and couriers have their own stacks. Brand-jacking will still abuse the Skroutz name nationwide because the story is on the front page.
What Skroutz Last Mile said
The customer letter, as carried by ProtoThema, frames data protection as a priority, names unauthorized access to a system storing parcel shipment data (full name, address, contact telephone), insists only those categories were affected, states cards/payment/credentials were not stored on Last Mile systems, says the company responded immediately with security measures, and stresses cooperation with competent supervisory authorities.
Fraud guidance in the same letter is concrete: be cautious of messages that do not come from official Skroutz Last Mile channels; watch suspicious emails or SMS that try to obtain personal information or passwords. That is the right shape of advice for a courier breach. It is not a root-cause post-mortem. No IOCs, no malware family, no named affiliate.
eKathimerini’s shorter English write-up matches those points and adds the scale context: Last Mile handled 70% of Skroutz orders in 2025 versus 52% in 2024. That growth line is business reporting, not a breach census. Use it to understand why a Last Mile system matters to Greek e-commerce — not to estimate row counts.
Industry context: marketplace couriers are high-value contact graphs
European marketplace logistics sit where identity, location, and timing meet. Attackers who cannot reach a payment vault still profit from knowing which apartment expects a box on Thursday. Greece’s e-commerce boom made Skroutz a household brand; Last Mile’s rising share of those orders made its shipment database correspondingly valuable.
Courier and last-mile breaches elsewhere in 2025–2026 have followed a familiar pattern: limited financial fields in the courier silo, loud phishing weather afterward, slow or missing public censuses. The Skroutz Last Mile data breach fits that pattern. The difference for Greek readers is local language and local locker culture — orange Skroutz Points are a recognizable visual hook for fake “locker expired” pages.
Under GDPR, unauthorized access to personal data processing systems is a personal-data breach whether or not a ransomware blog posts screenshots. Supervisory cooperation language in the notice is the company saying it is treating this as a regulatory matter, not a quiet IT ticket. HDPA outcomes, if any, will lag the customer SMS campaign by months.
Was I affected by the Skroutz breach?
Skroutz Last Mile has not published a public “check your email” portal in the coverage reviewed here. There is no attested nationwide count. Practical rule:
- You used Skroutz with Last Mile delivery or a Skroutz Point → assume name, address, and phone exposure until told otherwise.
- You only browsed Skroutz and never checked out → outside the shipment database, still inside the phishing audience.
- You paid by card on Skroutz → the company says card data was not on the Last Mile systems in this incident; still watch for card phishing that claims otherwise.
Do not upload your Greek ID or tax number to a random “Skroutz breach checker.” Do not send a selfie to a Telegram “Last Mile support” admin.
What you should do after the Skroutz Last Mile breach
- Read a primary write-up — ProtoThema’s English piece carries the company letter; eKathimerini confirms the same field list. Bookmark one. Ignore “security update” links in SMS.
- Expect delivery phishing for weeks. Any message that already knows your name and street is not automatically real.
- Never pay a “redelivery,” “customs,” or “locker storage” fee from a link in SMS or Viber. Use the Skroutz app or site you already have installed, typed by you.
- Never give a one-time code, password, or card number to someone who called you about a parcel. Couriers do not need your Skroutz password to finish a delivery.
- If a caller cites this breach as a reason to “re-verify” your account, hang up. The company already said credentials were not in the incident.
- Watch for SIM-swap and bank SMS that reference a package you actually ordered. Call your mobile operator or bank using numbers you already know.
- Tell household members who might answer the door or the shared phone.
- Merchants: warn warehouse staff that “Skroutz IR” will not call asking for VPN passwords or label-printer remote access.
- If you see misuse, document the message (date, number, what they already knew) and report through official Skroutz/Last Mile support channels you type yourself — plus Greek police cybercrime channels if money moved.
Phishing examples tied to this incident
- “Skroutz Last Mile: unauthorized access detected — confirm your phone to keep deliveries”
- “Your package is held at Skroutz Point — scan QR to unlock”
- “HDPA / data protection fee of €1.90 required after the Last Mile leak”
- “Driver photo verification required — upload ID front and back”
- Lookalike domains swapping characters in “skroutz” or “lastmile”
The tell is urgency plus a request for something Last Mile already has (your address) or should never need (your password, card, ID scan). Hang up. Open the real app.
What the company did not say
No public malware family. No named threat group. No statement that data was or was not exfiltrated beyond “unauthorized access” to the system storing those fields. No offer of credit monitoring in the English coverage (Greek consumer credit products differ from US-style freezes anyway). No FAQ with a row count.
Absence of a count is not absence of impact. A logistics contact graph is useful the day it leaks and useful six months later when a scammer quotes a real street number you forgot you ordered to.
How this compares to other shipping and marketplace leaks
Hardware-wallet and electronics fulfilment leaks (order tracking plugins, 3PL Metabase dashboards) also hand attackers a name and a door. Those stories often include email and sometimes purchase SKU. Skroutz Last Mile’s attested inventory is narrower — name, address, phone — and explicitly excludes payment and credentials on the courier systems. That is better than a KYC dump with national IDs. It is still enough for high-conversion local phishing in Greek.
Marketplace parent vs courier subsidiary matters for architecture. Shoppers think “Skroutz got hacked.” Technically the notice is Skroutz Last Mile’s IT system for shipments. Payment vaults and account credentials, the company says, live elsewhere and were not on the affected hosts. Keep that distinction when you triage panic texts — and when you write incident tickets if you are on the merchant side.
Canonical record and sources
Canonical BreachHistory page: 2026 Skroutz Last Mile — unauthorized access to parcel shipment data.
Sources: ProtoThema English customer-notice coverage; eKathimerini courier breach report (includes 70% / 52% order-share figures).
For people waiting on a package this week
Real drivers still deliver. Real locker codes still arrive through channels you already use. The breach does not mean every orange van is fake. It means strangers may know which street expects a box. If something feels off — a fee request, an ID upload, a password reset “because of Last Mile” — stop and use the logged-in Skroutz experience you trust.
If your order is legitimately delayed, the status lives in the Skroutz order page, not in a new domain registered yesterday. Type the hostname. Do not click.
For Greek merchants on Skroutz
Your buyers will forward you panic screenshots. Point them at the company’s field list: name, address, phone; not cards; not passwords. Do not collect “re-verification” forms yourself. Do not ask customers to paste OTPs into merchant chat. If your own staff use Last Mile portals, rotate portal passwords and MFA because shipment ops accounts are high-value even when the public notice is about customer contact fields.
Review who in your warehouse has access to bulk label exports. A marketplace courier breach is a reminder that your side of the shipping API can be the next soft target.
Regulatory posture
The notice says Skroutz Last Mile is cooperating with supervisory authorities. Under Greek and EU rules, that typically means the Hellenic Data Protection Authority is in the loop for a personal-data breach involving customer contact data. Public reprimands or fines, if they come, will be their own news cycle. Customer phishing will not wait for that cycle.
If you are a journalist or researcher waiting for a census: company silence on headcount is common in early EU notices when forensics are still scoping historical shipment tables. BreachHistory will update the catalog row if Skroutz Last Mile or a regulator publishes a verified count. Telegram screenshots are not that update.
Reading “credentials were not affected”
The company is saying Last Mile systems did not hold passwords or payment secrets for this incident. Scammers will invert that sentence: “Because of the Last Mile leak, Skroutz needs you to reset your password now.” That is still phishing. Password resets that matter start inside the account you already control, not from a courier SMS.
Same for cards. “Update your Visa after the Skroutz breach” is a classic follow-on even when the courier never stored PANs. Check your bank app for real charges; do not enter card digits into a “Skroutz security” page from a text.
FAQ
Were my credit cards stolen from Skroutz Last Mile? The company says credit card and payment data were not affected because they are not stored on the affected Last Mile systems.
Was my Skroutz password leaked? The company says credential data were not affected and are not stored on those systems.
How many people were hit? Unpublished as of the 23 September 2026 notices covered here. Do not trust random social-media figures.
Does Last Mile deliver most Skroutz orders? eKathimerini reports Last Mile handled 70% of Skroutz orders in 2025 (52% in 2024). That is market share, not a breach census.
Should I cancel my Skroutz account? Optional preference, not a forensic requirement. Cancelling does not retract a copy of a past shipping address if it already left.
Will Skroutz pay for monitoring? The English customer letter summarized in trade press focuses on phishing caution and containment, not a US-style credit-monitoring enrollment code.
What remains open
Root cause, exact systems, exfiltration volume, and affected population are still open. The verified facts are enough to act: treat name, address, and phone as potentially exposed if Last Mile touched your order; treat card and password panic texts as hostile until proven otherwise; keep using official apps you type yourself.
Skroutz Last Mile’s September 2026 notice is a logistics-privacy story with national reach in Greece. The missing census does not make the phishing weather optional. Assume the contact fields travel; assume the payment vault did not; act.