Greek courier company Skroutz Last Mile has disclosed a data breach after unauthorised access to one of its information systems exposed personal details linked to parcel deliveries.
The compromised information included customers’ names, delivery addresses and telephone numbers, according to a notification sent by the company to affected users on Wednesday. Skroutz Last Mile said credit card data, payment information and passwords were not exposed because those details were not stored on the affected system.
Greek media reported that several tens of thousands of customers may have been affected, although the company has not disclosed an exact number publicly.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
Company says unauthorised access was contained
Skroutz Last Mile said it detected unauthorised access to an IT system used to store information associated with parcel shipments.
After identifying the incident, the company said it took measures to investigate and contain the breach and began working with the relevant regulatory authorities.
Customers whose data was affected were notified directly.
The information exposed was limited to contact and delivery details, according to the company. That included names, addresses and telephone numbers.
Skroutz Last Mile specifically said payment credentials, credit card information and account passwords were not affected because the company does not store such data in the compromised systems.
The company has not publicly identified how attackers gained access, how long the intrusion lasted or whether data was downloaded in bulk.
Those details may emerge as the investigation continues.
Why delivery data can still be valuable to criminals
The absence of card details does not make the incident harmless.
A combination of a customer’s name, phone number and delivery address can provide criminals with enough information to create convincing phishing or impersonation attempts.
An attacker who knows that a person uses a particular courier service could pose as a delivery agent and claim that a parcel is delayed, that an address needs to be confirmed or that a small delivery fee must be paid.
The victim may be more likely to trust such a message because the sender already knows their name and address.
This is known as social engineering.
Instead of directly hacking a bank account, criminals use genuine personal information to make a fake call, message or website look credible.
Skroutz Last Mile has not said that the exposed information has been used in any follow-up scams.
Courier company handles large share of Skroutz deliveries
Skroutz Last Mile is the delivery arm of Skroutz, one of Greece’s largest e-commerce platforms.
Its role in the wider Skroutz ecosystem has expanded rapidly.
The courier network handled around 70% of orders placed through Skroutz in 2025, compared with about 52% in 2024, according to Greek reporting.
That scale means its systems can hold large volumes of delivery-related information.
Courier and logistics companies are particularly attractive targets because they process addresses, phone numbers and shipment information for large numbers of consumers.
Even where financial information is stored separately, exposed delivery data can still enable highly targeted fraud.
Regulatory scrutiny could follow under GDPR
Because Skroutz Last Mile operates in Greece, the incident falls within the European Union’s General Data Protection Regulation framework.
Under GDPR, organisations that suffer certain types of personal-data breaches may be required to notify the relevant data-protection authority and, where there is a high risk to individuals, inform affected users.
Skroutz Last Mile said it had taken the required steps in cooperation with the relevant regulatory authorities.
The Greek Data Protection Authority has not, at the time of writing, publicly announced a formal enforcement action relating to the incident.
That does not mean no regulatory process is underway.
Authorities may examine whether appropriate technical safeguards were in place, how quickly the company detected and contained the breach and whether customers were informed adequately.
Precise scale and attack method remain unclear
Several important questions remain unanswered.
The company has not publicly disclosed the precise number of affected customers, whether attackers copied the data or merely gained access to it, or which vulnerability or account was used to enter the system.
CNN Greece reported that the affected population is estimated to be in the several tens of thousands.
There is also no public confirmation that the stolen information has appeared on cybercrime forums or been offered for sale.
Until those details are known, the most immediate risk for affected users is likely to be phishing and impersonation rather than direct theft of payment credentials.
Customers should therefore be particularly cautious about calls or messages claiming to be from Skroutz, delivery drivers or courier support teams.
A message containing a correct address or phone number should not be treated as proof that the sender is genuine.
What this means for you: If you receive a delivery-related call or message after the breach, do not click payment links or share verification codes simply because the sender knows your name or address. Verify parcel information directly through the official Skroutz or courier platform.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics