About 33,054 Linzhumai users or customers may have been affected by a suspected cyberattack, according to an initial assessment by the Privacy Commissioner’s Office. The investigation remains ongoing, and the figure is not a final confirmed total.

Linzhumai said it discovered on 24 August that its system might have been subjected to a cyberattack, with some data potentially accessed without authorisation. The Privacy Commissioner’s Office received a data breach notification on 30 August. On 1 September, the platform issued a notice saying the system was suspected to have been attacked, while continuing to co-operate with the investigation.

The data potentially involved may include names, addresses, email addresses, telephone numbers and online shopping order details. The platform also listed purchased goods, collection points and delivery addresses. The precise scope remains subject to investigation.

Linzhumai said login passwords, credit card details and bank account information were not involved. This is the platform’s position while the incident is being investigated.

Police said they had received six cases in the previous week involving people impersonating Linzhumai customer service staff, with losses exceeding HK$300,000. The reported scams used reasons including deposits, lost parcels and refunds to persuade victims to transfer money or provide more personal information. The reports do not establish a link between these scams and the suspected breach.

Linzhumai said it had reported the incident to police and the Privacy Commissioner’s Office and was co-operating with the investigation. The Privacy Commissioner’s Office urged potentially affected people to stay alert, consider changing online account passwords and enable multi-factor authentication, and monitor suspicious messages, account logins and bank transactions. The final number of affected people, the confirmed data categories and any connection between the suspected breach and the impersonation scams have yet to be established.