---
title: Data Breach at German Supermarket Chain tegut
description: Tegut, which operates around 280 supermarkets across Germany, was recently the victim of a cyberattack that included the theft of personal data.
image: https://insights.comforte.com/hubfs/blog%20header%20data%20breach%20at%20german%20supermarket%20chain%20tegut.jpeg
---

[![Hubspot_blog_logo](https://insights.comforte.com/hs-fs/hubfs/Hubspot_blog_logo.png?width=295&name=Hubspot_blog_logo.png)](http://www.comforte.com)

[![Subscribe](https://no-cache.hubspot.com/cta/default/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0)

[![blog header data breach supermarket tegut](https://insights.comforte.com/hubfs/blog%20header%20data%20breach%20at%20german%20supermarket%20chain%20tegut.jpeg)](https://insights.comforte.com/data-breach-at-german-supermarket-chain-tegut)

[Dan Simmons](https://insights.comforte.com/author/dan-simmons) l Jun 1, 2021 l [Compliance](https://insights.comforte.com/tag/compliance), [Data Breaches](https://insights.comforte.com/tag/data-breaches), [EMEA](https://insights.comforte.com/tag/emea)

# Data Breach at German Supermarket Chain tegut

The German supermarket chain "tegut" was recently the [target of a cyberattack](https://www.spiegel.de/netzwelt/web/tegut-nach-hackerangriff-tauchen-interne-daten-im-darknet-auf-a-06d52a1a-b5df-4601-b7a6-c295d1cd9e8a) (source in German) and on April 24 the company activated emergency procedures that shut down their entire central IT network and disconnected it from the internet. While done to limit the exposure of sensitive data, these measures also had side effects including gaps in their supply chain and other services that lasted for weeks. Despite these mitigation efforts, the attackers have already begun to publish company and customer data on the dark web.  

[Tegut](https://en.wikipedia.org/wiki/Tegut) is a Swiss-owned supermarket chain that operates about 280 stores across central and southern Germany. They have had an [annual turnover of over 1 billion EUR](https://de.statista.com/statistik/daten/studie/874832/umfrage/umsatz-von-tegut/#:~:text=Die%20Statistik%20zeigt%20den%20Umsatz,1%2C26%20Milliarden%20Euro%20netto.) every year since 2017.

## What kind of data was affected? 

According to a [press release from May 27](https://www.tegut.com/aktuell/artikel/cyberangriff-weitere-unternehmensdaten-im-darknet-aufgetaucht.html), the attackers began publishing answers that customers had given to market research surveys, primarily those who were members of their customer rewards program "GuteKarte". The leaks also included personal data, including home addresses, email addresses, and telephone numbers.

A week before that, [it was announced](https://www.tegut.com/aktuell/artikel/cyberangriff-unternehmensdaten-von-tegut-im-darknet-veroeffentlicht.html) that company data had been published online. According to the press release from May 18, it could not be ruled out that the affected company data included personal data of employees. 

## What services were affected during the shutdown?

Due to the emergency shut down, customers and employees experienced the following issues: 

- The email server was shut down so requests couldn't be sent to the company per email. This service was restored on May 9.
- Certain products were unavailable for a time because the central logistics program was taken offline and wasn't able to automatically process the need for restocking.  [Stores had to manually track their stock](https://www.hessenschau.de/wirtschaft/hackerangriff-sorgt-fuer-ausgeduennte-tegut-regale,tegut-nach-cyberangriff-100.html) and, while the email server was shut down as well, restocking orders had to be placed via telephone.
- Most types of gift certificates couldn't be purchased or processed for payment until May 21.
- Certain areas of their website had to be deactivated, including the customer login portal, which came back online on May 25 and required customers to change their passwords.

## What motivated the attack? 

The company has suggested that the incremental release of the stolen data by attackers is intended to increase "pressure" on them. In the press release following the second publication of stolen data, the company's CEO commented (translated from German), "we will not reward criminal activity and we will not enter into negotiations with criminals. It is clear to us that the attackers are now increasing the pressure on \[our company\] and want to provoke uncertainty among our customers, employees, and suppliers in order to assert their demands." It was not revealed in the press release what those demands are.

## How has the company responded?

- Emergency protocols were activated on April 24 which involved shutting down the company's central IT network and disconnecting it from the internet. 
- Since then, regular press releases have been published and chronicled on their website. 
- Customers were asked to change their passwords before logging back into their online portal. 
- The breach has been reported to the authorities and affected customers have been notified. 
- A new logistics app has been released ahead of schedule that enabled stores to begin restocking their shelves as quickly as possible.

## What can organizations do to mitigate attacks like this?

The number of data breaches continues to rise. According to [ENISA's Threat Landscape 2020](https://www.enisa.europa.eu/publications/enisa-threat-landscape-2020-data-breach), the total number of breaches by midyear 2019 increased by 54% compared to midyear 2018. 

Cybercriminals are constantly looking for new ways to breach organizations and are finding ways to exploit value from any kind of data they are able to access. While [payment card data is o](https://insights.comforte.com/what-to-expect-from-pci-dss-4.0?hsLang=en)ften the main focus, hackers will also resort to using personal data from customers to blackmail organizations.

Whether the concern is accidental exposure or external attackers like in this scenario, the best strategy is to assume that sooner or later, sensitive data at your organization is going to be compromised, one way or the other. That is why the focus shouldn't solely be on protecting the containers that data is stored in, but rather the data itself should be protected in a [data-centric security](https://www.comforte.com/data-security) approach. That way, in the likely event of a breach, attackers will find themselves in a proverbial empty vault full of obfuscated data with no exploitable value.

A data-centric security strategy starts with the assumption that the organization has already been compromised and therefore, whenever possible, sensitive data must be protected throughout the organization wherever live data had been used formerly. In many situations, live data can be replaced with operationally and functionally equivalent data elements that still enable operations and analytics, yet have no discernable value to any person who may gain unauthorized access to them. The outcome is that attacks and accidental exposures are more difficult, detectable, and manageable than they are with the traditional perimeter based defenses, monitoring, and controls.

---

| Share this:  | [![LinkedIn](https://insights.comforte.com/hubfs/Social%20Icons/linkedin%20icon.png)](https://www.linkedin.com/shareArticle?mini=true&url=https://insights.comforte.com/data-breach-at-german-supermarket-chain-tegut&utm_medium=social&utm_source=linkedin) | [![Bluesky](https://insights.comforte.com/hubfs/Social%20Icons/bluesky_logo.png)](https://bsky.app/intent/compose?url=https://insights.comforte.com/data-breach-at-german-supermarket-chain-tegut&utm_medium=social&utm_source=Bluesky) | ![Twitter](https://insights.comforte.com/hubfs/Social%20Icons/twitter_x_logo-1.png) | [![XING](https://insights.comforte.com/hubfs/Social%20Icons/xing-color2.png)](https://www.xing.com/spi/shares/new?url=https://insights.comforte.com/data-breach-at-german-supermarket-chain-tegut&utm_medium=social&utm_source=xing) | [![Email](https://insights.comforte.com/hubfs/Social%20Icons/email%20icon.png)](mailto:?subject=Check%20out%20https://insights.comforte.com/data-breach-at-german-supermarket-chain-tegut&utm_medium=social&utm_source=email%20&body=Check%20out%20https://insights.comforte.com/data-breach-at-german-supermarket-chain-tegut&utm_medium=social&utm_source=email) |
| --- | --- | --- | --- | --- | --- |

## Want to learn more?

Data-centric security protects the data itself so that even in the event of a breach, no exploitable data is exposed. There are many cases were processes can be carried out on data while it's still in a protected state, allowing digital organizations to continue humming along while keeping sensitive data safe. To learn more, check out our data protection platform solution brief:

[![Download Solution Brief](https://no-cache.hubspot.com/cta/default/4026697/7962e9ff-2c50-4207-910f-fc5fd97083e7.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/7962e9ff-2c50-4207-910f-fc5fd97083e7)

### Related posts

![How Vaultless Tokenization Works in Practice, to Transform Your Business](https://insights.comforte.com/hubfs/comforte%20AG_How%20Vaultless%20Tokenization%20Works%20in%20Practice%20to%20Transform%20Your%20Business_24.07.2025.png)

 Jul 24, 2025 l [PCI DSS](https://insights.comforte.com/tag/pci-dss) , [Compliance](https://insights.comforte.com/tag/compliance)

### [How Vaultless Tokenization Works in Practice, to Transform Your Business](https://insights.comforte.com/how-vaultless-tokenization-works-in-practice-to-transform-your-business?hsLang=en)

In last month’s [blog post](https://insights.comforte.com/is-pci-dss-4.0-slowing-you-down-heres-how-comforte-can-accelerate-your-pci-compliance-journey?hsLang=en) we explained how vaultless tokenization can transform PCI DSS 4.0 compliance from a regulatory burden into a business enabler. Not only does vaultless tokenization reduce the scope and cost of compliance, but it also...

[Read more](https://insights.comforte.com/how-vaultless-tokenization-works-in-practice-to-transform-your-business?hsLang=en)

![Is PCI DSS 4.0 Slowing You Down? Here’s How comforte Can Accelerate Your PCI Compliance Journey](https://insights.comforte.com/hubfs/comforte%20AG_Is%20PCI%20DSS%204.0%20Slowing%20You%20Down_%20Heres%20How%20comforte%20Can%20Accelerate%20Your%20PCI%20Compliance%20Journey%20.png)

 Jun 26, 2025 l [PCI DSS](https://insights.comforte.com/tag/pci-dss) , [Compliance](https://insights.comforte.com/tag/compliance)

### [Is PCI DSS 4.0 Slowing You Down? Here’s How comforte Can Accelerate Your PCI Compliance Journey](https://insights.comforte.com/is-pci-dss-4.0-slowing-you-down-heres-how-comforte-can-accelerate-your-pci-compliance-journey?hsLang=en)

With the latest version of PCI DSS, the Payment Card Industry Security Standards Council (PCI SSC) aims to elevate the standards for cardholder data (CHD) security with themes like stronger cryptography, multi-factor authentication, and continuous...

[Read more](https://insights.comforte.com/is-pci-dss-4.0-slowing-you-down-heres-how-comforte-can-accelerate-your-pci-compliance-journey?hsLang=en)

![Streamlining PCI DSS 4.0 Compliance for IBM Z Series Customers](https://insights.comforte.com/hubfs/comforte%20AG_Streamlining%20PCI%20DSS%204.0%20Compliance%20for%20IBM%20Z%20Series%20Customers.png)

 May 15, 2025 l [Data Protection](https://insights.comforte.com/tag/data-protection) , [Compliance](https://insights.comforte.com/tag/compliance)

### [Streamlining PCI DSS 4.0 Compliance for IBM Z Series Customers](https://insights.comforte.com/streamlining-pci-dss-4.0-compliance-for-ibm-z-series-customers?hsLang=en)

IBM Z Series customers traditionally include some of the world’s biggest financial services and retail companies. This puts them firmly in the crosshairs of the Payment Card Industry Data Security Standard (PCI DSS). Yet while compliance can be...

[Read more](https://insights.comforte.com/streamlining-pci-dss-4.0-compliance-for-ibm-z-series-customers?hsLang=en)

### Service

- [Contact](https://www.comforte.com/contact/)
- [About us](https://www.comforte.com/company/)
- [Blog](https://insights.comforte.com/)
- [Press Releases](https://www.comforte.com/company/press-releases/)
- [Career](https://www.comforte.com/company/career/)
- [Resources](https://www.comforte.com/resources/)

### Germany

comforte AG  
Abraham-Lincoln-Str. 22   
65189 Wiesbaden  
Germany

Phone: + 49 611 93199 00  
Fax: + 49 611 93199 05

### Australia

comforte PTY  
Suite 20, 1 Rivett Road  
North Ryde  
NSW 2113  
Australia

Postal Address:   
PO Box 1710  
Lane Cove  
NSW 1595  
Australia

Phone: +61 2 8197 0272

### USA

comforte Inc.  
30 Wall Street, 8th Floor  
New York, NY 10005-2205  
USA

Phone: +1-646-438-5716

### Singapore

comforte Asia Pte. Ltd.   
1 Raffles Place, #19-61 Tower 2   
Singapore 048616

Phone: +65 6808 5507

- [Sitemap](https://www.comforte.com/sitemap/)
- [Legal Notice](https://www.comforte.com/legal-notice/)
- [Privacy Policy](https://www.comforte.com/privacy-policy/)

© comforte AG 2026

<https://x.com/comforteag> <https://www.youtube.com/c/comforte-ag> <https://www.linkedin.com/company/comforte-ag/>