← Coles Group

2023 Coles Group — historical Coles-branded cardholder data in Latitude Financial mega-breach

2023 Unknown records affected Share on X

Data compromised

Historic credit-card applicant and account-holder PII as described in Latitude-era breach reporting—driver licence, passport, and contact/demographic fields cited at portfolio level

Technical writeup

In April 2023, Coles publicly confirmed that personal information used for historical Coles-branded credit cards (issued prior to its 2018 migration away from the Latitude/GE Money-era program) was caught up in the Latitude Financial compromise—part of a wider incident Latitude described as affecting on the order of tens of millions of combined records across Australia and New Zealand partner portfolios. Coles’ own statements in the first press wave did not publish a standalone count of Coles-only victims, framing notification as flowing from Latitude as former program operator.

Root cause

Criminal intrusion into Latitude Financial and connected legacy retailer finance datasets (third-party / former affiliate processor context)

References