BREACHransomwarelive13 Jun 2026

Ransomware: lapsus$ claims INGKA GROUP (SE) — Consumer Services

BREACH. Sourced from ransomwarelive, summarised by Matproof.

AI Analysis

What changed and what to do.

On June 13, 2026, a ransomware group known as Lapsus$ claimed responsibility for a cyberattack against INGKA GROUP, the parent company of IKEA, in the consumer services sector. The claim was published on the ransomware monitoring platform ransomware.live, which tracks and verifies such incidents. While the full extent of the data breach is not yet confirmed, the incident signals a significant security event that may involve customer or operational data exposure, triggering notification obligations under the EU General Data Protection Regulation and other breach reporting frameworks.

This development primarily affects INGKA GROUP and its subsidiaries, but it also serves as a warning for all organizations in the retail, consumer services, and e-commerce sectors across the EU. These sectors are frequent targets for ransomware groups due to their large customer databases and reliance on digital supply chains. Compliance teams in similar organizations should assess their own exposure to similar threats, particularly if they handle personal data or operate critical infrastructure.

Compliance teams should immediately verify whether their organization has any shared service providers or data processing links with INGKA GROUP. They should also review their incident response plans to ensure they can meet the 72-hour breach notification deadline under GDPR. Additionally, teams should reinforce employee training on phishing and credential theft, as Lapsus$ is known for social engineering tactics. Finally, monitor official updates from INGKA GROUP and relevant data protection authorities for further guidance on containment and remediation steps.

View original at ransomwarelive

This summary is AI-generated for orientation purposes. For regulatory action, always consult the original source linked above.

More BREACH updates

Latest in BREACH.

← Back to all updates
Live regulatory monitoring

Never miss a compliance update.

Get weekly digests of DORA, NIS2, GDPR, MaRisk, and ISO 27001 changes — straight to your inbox. Free.

No spam. Weekly digest only. Unsubscribe anytime.

DORANIS2GDPRMaRiskISO 27001

Map this to your controls

Connect regulatory changes to your compliance work.

Matproof maps every regulator update directly to your controls and surfaces the ones that affect your organisation — across 21 frameworks.

Book a DemoBrowse all updates
Ransomware: lapsus$ claims INGKA GROUP (SE) — Consumer Se… — BREACH | Matproof