Tesco customers' passwords and email details leaked online
More than 2,000 of the supermarket giant's customers affected by online data leak.
Supermarket giant Tesco has deactivated more than 2,000 of its customers' online accounts after their personal details were published on text sharing site Pastebin.
The leaked details included the email addresses, plain text passwords and Tesco Clubcard point balances of 2,239 of the company's customers.
According to a report by the BBC, the data may have been pieced together by hackers using information lifted from other sites and cyber attacks.
It is thought the gleaned email addresses and passwords were then systematically used by hackers to try and access Tesco.com accounts.
In a small number of cases, the hackers are said to have stolen Clubcard points from customers too, which Tesco has agreed to reimburse.
In a statement on the Tesco Facebook page, the company said it was investigating the breach.
"We take the security of our customers' data extremely seriously and are urgently investigating these claims," a company spokesperson wrote.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
"We are committed to ensuring that nobody misses out as a result of this. We will issue replacement vouchers to the very small number who are affected."
Trey Ford, global security strategist at security vendor Rapid 7, said the case highlights the perils of using the same login details across multiple online accounts.
"So far the information available indicates the impact of this has been relatively limited stolen vouchers but if attackers have tried this on Tesco.com, the chances are they are also trying it on other sites too and so we may see additional fallout," said Ford.
"This is [a lesson] in consumer behaviour people continue to reuse passwords and other credentials across multiple sites, making it easy for attackers to compromise them. It's essential to learn the lesson from this incident before the cost becomes greater," he added.
Caroline Donnelly was the news and analysis editor of IT Pro. Previously, she worked as a reporter at several B2B publications, including UK channel magazine CRN, and as features writer for local weekly newspaper, The Slough and Windsor Observer. She studied Medical Biochemistry at the University of Leicester and completed a Postgraduate Diploma in Magazine Journalism at PMA Training in 2006.
-
The OpenAI and Anthropic containment breaches are a bit spooky, but also quite sillyOpinion An AI leaving notes to future versions of itself is pure sci-fi; forgetting to lock down an environment is prosaic
-
Bringing data to the heart of AISponsored AI is changing our approach to data, find out how HPE Alletra Storage can help your business
-
1Password teams up with Anthropic to give Claude access to your credentialsNews A new ‘zero-exposure’ security framework allows agents to use stored credentials in the 1Password vault
-
We need to do something about passwordsPasswords are a fundamental aspect of access security, but recent password leaks have undermined their ability to protect data
-
Dashlane lifts the lid on attack that saw hackers download encrypted user vaultsNews The company said it has now informed all affected customers, and taken action to shut down the operation
-
The NCSC says it’s time to switch to passkeysNews UK security organization calls for companies to step up and offer more secure ways to login
-
AI agents are creating new identity security risks: 1Password wants to solve thatNews The Unified Access system from 1Password will help enterprises manage AI agent access across different devices and users
-
Using AI to generate passwords is a terrible idea, experts warnNews Researchers have warned the use of AI-generated passwords puts users and businesses at risk
-
Researchers called on LastPass, Dashlane, and Bitwarden to up defenses after severe flaws put 60 million users at risk – here’s how each company respondedNews Analysts at ETH Zurich called for cryptographic standard improvements after a host of password managers were found lacking
-
Thousands of exposed civil servant passwords are up for grabs onlineNews While the password security failures are concerning, they pale in comparison to other nations