NEWS Hackers took out of IKEA 180 GB of confidential data. The company faces loss of control over internal supplies

Gold Surfer

Administrator
Staff member
Administrator
Moon-Club
Exclusive
Infinity
Premium
Member
Joined
Jan 20, 2026
Messages
345
Reaction score
2,663
The network included drawings of the entire digital architecture of the Swedish brand.
1780481556885.png
IKEA is checking the statement of the hacker group Lapsus$, which claims to have received 180 GB of internal data Ingka Group, the largest franchisee of the brand. The company operates hundreds of IKEA stores and digital channels in 32 countries, so even an unconfirmed leak quickly became a notable event for the market.

According to Cybernews, the attackers posted an ad on their website and announced the sale of an array of data. It is not about client records, but about internal repositories with source code, diagrams of the global e-commerce architecture, logistics systems, cloud infrastructure and projects related to AI and MLOps.

IKEA has not yet confirmed the hack. A representative of the company said that IKEA is aware of the statements of Lapsus$ and examines the available information. Until the completion of the inspection, the company did not disclose additional details.

In the published sample, Cybernews experts found about 6300 catalog names. According to the authors of the report, the file shows only the structure of directories, without content. Therefore, it is not yet possible to say for sure whether the repositories contain source code, configuration files, credentials, internal documentation or customer information.

Even in the absence of personal data, such a leak can be dangerous. Source code and technical schemes help to understand how internal applications are arranged, what technologies the company uses and where weaknesses can be located. For the attackers, such materials are turned into a map of infrastructure, according to which it is easier to prepare new attacks.

Cybernews links a statement to Lapsus$, a group that earns on extortion without classic file encryption. Instead of blocking systems, attackers steal data and threaten to publish. The main method of the group is considered to be social engineering.

Lapsus$ has already been linked to attacks on Microsoft, Uber, Nvidia, Samsung, Okta and Rockstar Games. In 2026, the group also announced the hacking of Adidas, AstraZeneca and Vodafone. In mid-2025, Lapsus$ merged with Scattered Spider and Shiny Hunters into a larger association known as Scattered Lapsus$ Hunters.

So far, the main detail remains unconfirmed. The public sample shows only the names of the folders, not the files themselves. But if the stated amount of data and the composition of the repositories are confirmed, IKEA will face not only a reputational strike, but also the risk of subsequent attacks on internal services and supply chains.
 
6,416Threads
86,534Messages
6,082Members
Zero OneLatest member
Top Bottom