What Happened
In early 2026, dark web monitoring sources reported an alleged data breach involving Haagplanten.net, an online European garden plants and hedges retailer, after a threat actor began circulating what they claimed was the site’s customer database. The leaked sample reportedly contains sensitive personally identifiable information, including full names, email addresses, phone numbers, physical/home addresses, and VAT (tax) numbers, along with technical fields such as “Account Lock” that suggest active account credentials or authentication status may also be exposed. Victims appear to be spread across Europe, particularly in France, Germany, and the Netherlands. While the exact number of affected records and precise breach date have not been publicly confirmed, the nature of the exposed data raises significant risks of GDPR violations, business email compromise and invoice fraud, targeted delivery-themed phishing and smishing, and potential account takeover if associated passwords or hashes were included in the dump.
