Data breach in Holmasto’s customer register
Published on September 2, 2026
A data security incident affected our customer records on Sunday, August 30: a vulnerability was identified in our customer search interface, allowing an external automated system to retrieve a portion of data from our customer register.
What data may have been compromised?
The breach involves our customers’ names, contact details, addresses, and potentially personal identity codes and/or bank account numbers. We are currently investigating the full scope of the breach. We aim to contact you again as soon as possible to provide more specific details on which of your personal information was accessed without authorization. The breach affects our entire customer register, meaning information belonging to thousands of individuals in our register.
What measures have we taken?
The vulnerability was fixed immediately upon detection, and system data retrieval capabilities have been restricted. We have reported the incident to the Data Protection Ombudsman.
Recommended actions
Be cautious: We recommend that you exercise particular caution and remain critical of unexpected emails, phone calls, or messages requesting personal or other sensitive information. Do not click on suspicious links or reveal your online banking credentials or verification codes to anyone. Neither Holmasto nor your bank will ever ask for them via email or telephone.
We are deeply sorry for this incident. We are investigating the matter further and will be in touch again with everyone affected by the data breach.
Contact Information
For further information, please contact our customer service team at info@holmasto.fi