← Simian

2026 Simian (Drukland/Reclameland/Flyerzone) — third-party supplier breach; usernames/emails/hashes + limited cards

2026 500.0K records affected Share on X

Data compromised

Usernames, email addresses, hashed passwords (algorithm unpublished); credit-card details for a limited subset contacted individually. Company serves ~500,000 customers across brands — exact affected census unpublished; recordsAffected 500000 reflects customer-base scale under brand notices per press.

Technical writeup

Verified company disclosure — August 12, 2026. Dutch printing group Simian (Drukland, Reclameland, Flyerzone; ~500,000 customers in NL/BE) confirmed a security incident at an external service provider that exposed customer usernames, email addresses, and hashed passwords, plus credit-card details for a limited number of customers who were contacted individually. Cybernews and DutchNews cite password resets, blocked accounts, AP and police reports, and an external forensics firm. Simian stated the incident is unrelated to the separate CEVA Logistics wave. Exact headcount of affected individuals not published; BreachHistory indexes recordsAffected 500000 as the publicly cited customer-base scale under brand warnings, with card exposure limited to a smaller unpublished subset.

Root cause

Confirmed security incident at an external service provider used by Simian (not Simian’s own core origin per company); investigated with outside cybersecurity firm; reported to AP and police

References