Stokke, the Norwegian manufacturer of children’s furniture and baby gear known for products like the Tripp Trapp high chair, notified customers that a security incident involving one of its service providers exposed limited personal information connected to certain customer orders and returns. Companies that rely on third-party service providers to help fulfill and manage customer orders have a responsibility to ensure those providers protect customer data, and customers deserve to know when that protection fails.
Stokke’s Data Breach Investigation
According to Stokke’s notice, the company learned of a security incident involving a service provider that managed a limited amount of personal information relating to certain customer orders or returns. The service provider had no direct connection to Stokke’s own internal customer data storage systems. Upon learning of the incident, Stokke initiated an investigation with the service provider to determine the scope of the exposure and worked with the provider to implement corrective measures. Stokke has stated that the impact was limited and that the exposed information did not identify Stokke as the retailer associated with the order or return, and did not include detailed order information, payment card details, bank account information, passwords, customer account credentials, or postal addresses.
Stokke’s notice does not specify the exact date the incident occurred, how many customers were affected, or the identity of the third-party service provider involved. As of the date of the notice, Stokke stated that neither it nor the service provider had identified evidence that the exposed information had been misused, published, or used for fraudulent purposes.
Data breaches involving third-party service providers used for order fulfillment, customer service, or logistics are common across the retail industry, since companies routinely share limited customer information with providers to process transactions. Even when the exposed information is limited to contact details and order reference numbers, as in this case, that combination can still be used by bad actors to craft convincing phishing emails or text messages that reference a genuine past purchase, making the communication appear more legitimate than a random scam attempt. Customers should remain alert to unexpected messages referencing an order or return, even months after the underlying incident occurred.
When Did This Breach Occur?
Stokke’s notice does not specify the exact date the security incident at its service provider occurred or was discovered.
What Information Was Breached?
According to Stokke, the information accessed included customers’ email addresses, phone numbers, and an order or return reference number. Stokke stated that payment card details, bank account information, passwords, account credentials, and postal addresses were not included.
What You Can Do
If you have placed an order or return with Stokke, be cautious of unexpected emails, texts, or phone calls referencing an order or return, particularly any that ask you to click a link, provide payment information, share login credentials, or confirm personal information. Verify any communication by contacting Stokke directly through an official customer service channel rather than using contact information provided in a suspicious message. Consider monitoring your accounts for unusual activity as a general precaution.
File a Data Breach Lawsuit Against Stokke
If you were notified about this Stokke data breach, you may be entitled to compensation. Companies are expected to ensure their service providers safeguard customer data, and when that trust is broken, affected customers deserve accountability.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.