Skip to main content
  1. Home
  2. Phones
  3. Android
  4. Mobile
  5. News

Dixons Carphone hack exposes 5.9 million cards, 10 million accounts

Dixons Carphone underestimated data hack, now says 10 million affected

Add as a preferred source on Google

Prominent U.K. mobile technology retailer Dixons Carphone has been the victim of a massive data hack, in which payment details for 5.9 million customers were accessed illegally. The payment data was stored in the processing system of Currys PC World and Dixons Travel stores, the latter of which operates in airports. In addition to the payment details, Dixons Carphone initially said the names, addresses, and email addresses of 1.2 million people in the firm’s database had been accessed. In July, it then revised this number to 10 million.

The company says this information has not been used fraudulently, but is contacting affected customers nonetheless. Dixons Carphone said 5.8 million cards that were accessed were protected by chip-and-PIN payment protection, and the important card verification value number (CVV) printed on the back of payment cards was not stored, leaving the majority of customers free from immediate worry. However, the remaining 105,000 cards accessed in the hack were cards not issued in Europe and did not have chip-and-PIN protection. These cards were likely used at Dixons Travel stores by airport visitors, but Dixons Carphone says it hasn’t found evidence of fraud in these either.

Recommended Videos

Steps to avoid any payment fraud have already been taken by the group, and relevant card companies have been informed of the breach, helping to minimize the chances of further problems. After revealing the increase to 10 million accounts accessed, a Dixons Carphone representative told the BBC it is, “very sorry for any distress caused.”

The company has been investigating the breach since July 2017, indicating a considerable gap between discovering the security problem and the subsequent public announcement. The hack was discovered during a review of the firm’s systems and data, according to its statement on the matter, and it reassures customers the security holes have been closed and there has been no evidence of further snooping. It has subsequently said it is adding new security measures, and the investigation is helping to build a better picture of what happened, and has likely brought the increase in accounts accessed to light.

It’s not the first time the group has had security problems. In 2015 an attack on Carphone Warehouse left the details of 2.4 million customers exposed, along with the payment data of 90,000 people. It was subsequently fined 400,000 British pounds/$533,000 by the Information Commissioners Office (ICO) in 2018 — one of the largest fines it has issued. Retailer Dixons merged with Carphone Warehouse in 2014.

At the time, ICO commissioner Elizabeth Denham said: “A company as large, well-resourced, and established as Carphone Warehouse, should have been actively assessing its data security systems, and ensuring systems were robust and not vulnerable to such attacks.” We’d expect the agency to pay considerable attention to this second, more serious breakdown in security at the company.

Update on July 31: Added revised number of accounts accessed from 1.2 million to 10 million

Andy Boxall
Andy has written about mobile technology for almost a decade. From 2G to 5G and smartphone to smartwatch, Andy knows tech.
TSMC might set up a price hike that could come straight for your next phone, laptop, or tablet
Here's what TSMC's rumored 10% chip price increase actually means in dollar terms, and why your next phone or laptop could end up costing more.
TSMC Fab

My wallet flinched the second I saw the words "TSMC" and "price increase" in the same headline, and honestly, yours should too.

Turns out the company behind the silicon powering basically every flagship device out there, including Apple’s A-series and Qualcomm’s Snapdragon processors, is reportedly about to make all of it a little pricier.

Read more
Samsung’s free storage doubling for preorders is gone in Austria, and the replacement isn’t as sweet
Samsung's free storage doubling deal might just be history.
The back of the Galaxy Z Fold 7

If you've pre-ordered a Samsung foldable purely for the free storage bump, tomorrow's Unpacked event might sting a little.

For years, pre-ordering a new Galaxy meant automatically getting double the storage at no additional charge. Buy the 128GB model, walk away with 256GB for the same price. The same applied to the 256GB and 512GB models. However, that might change at the upcoming Galaxy Unpacked event. 

Read more
Apple fixes Hide My Email bug that exposed users’ real email addresses
Here's how Apple's Hide My Email flaw leaked real addresses for over a year, and why it only got fixed once the story went public.
apple-merging-sign-in-with-apple-hide-my-email-icloud+

Turns out the "Hide" part of Hide My Email wasn't doing its job quite as advertised, something that I covered early in July. Security researcher Tyler Murphy reported the flaw in June 2025, but despite Apple claiming it was resolved in March 2026, independent tests confirmed it remained exploitable, at least until July 3, 2026.

So how did this bug actually work?

Read more