The personal details of up to 2.4 million customers may have been accessed after a division of Carphone Warehouse was hit by a “sophisticated” cyber attack, the mobile phone retailer has said.
Up to 90,000 customers may also have had their encrypted credit card details accessed, it said in a statement.
An investigation carried out by the company found that names, addresses, dates of birth and bank details of customers could have been accessed.
A Carphone Warehouse spokesman said the attack was stopped “straight away” after its own systems discovered it on Wednesday afternoon.
Asked when the data breach began, he replied: “The evidence indicates within the last two weeks before Wednesday afternoon.”
Sebastian James, group chief executive of Dixons Carphone, said: “We take the security of customer data extremely seriously, and we are very sorry that people have been affected by this attack on our systems.
“We are, of course, informing anyone that may have been affected, and have put in place additional security measures.”
The affected division of Carphone Warehouse operates the websites OneStopPhoneShop.com, e2save.com and Mobiles.co.uk and provides services to iD Mobile, TalkTalk Mobile, Talk Mobile and some Carphone Warehouse customers.
The firm said in a statement: “On August 5 we discovered that the IT systems of a division of Carphone Warehouse in the UK had been breached by a sophisticated cyber-attack.”
It went on: “We took immediate action to secure these systems and launched an investigation with a leading cyber security firm to determine exactly what data was affected.
“We have also put in place additional security measures to prevent further attacks.”
Carphone Warehouse said it was contacting all customers who may have been affected to inform them of the breach and to advise them on how to reduce the risk of further consequences.