Data Breaches

Dustin Takes Orders by Phone, Cannot Yet Say What Attackers Reached

Dustin Takes Orders by Phone, Cannot Yet Say What Attackers Reached

Dustin is taking orders by telephone. A company that describes itself as an online based IT partner for the Nordics and Benelux has had its webshops in Sweden, the Netherlands and Belgium offline since shortly after noon on Thursday 3 September, when it told the market that unauthorised parties had reached some of its internal IT systems and that it had shut parts of its own environment down to contain them.

“Not a Technical Failure”

Dustin’s statement describes the incident as serious and confirms that external forensic specialists are engaged and that the police have been informed. It also says the company has filed an initial notification of a potential personal data breach with IMY. Head of communications Eva Ernfors told EFN that the shutdown was Dustin’s own decision rather than one the attackers forced and described the cause as unauthorised access rather than a technical failure. The shares fell as much as 6 percent on the day, according to MarketScreener.

On Tuesday morning, five days on, Dustin said the order flow had been restarted and that customers could place orders by phone and email while it worked to reopen the web and customer portals. Ehandel.se reports that every system returning to production is validated first. The websites still carried an outage notice on Tuesday afternoon.

Support and Administration Systems

The one piece of forensic detail Dustin has released is that initial findings point to the attackers having had access to internal support and administration systems. Nothing so far indicates customer data has leaked although the company says that cannot yet be ruled out. Support and administration systems are where a reseller keeps customer contacts, order history, delivery addresses, serial numbers and support tickets which is precisely the material that makes a follow-on wave of invoice fraud or phishing against Dustin’s customers credible. That is the pattern of the Ceva Logistics breach in August.

Read “nothing so far” for what it is, a snapshot from an investigation that, in Dustin’s own words on Tuesday, is still working to identify which data is covered. The company has already judged the risk to individuals real enough to notify IMY. GDPR only requires that notification when a breach is likely to put people at risk.

Everything else is absent. Dustin has not said how the attackers got in, how long they had been inside before Thursday, whether anything was copied out or who it believes was responsible, Ernfors declined to discuss attribution when Dagens industri asked. Cyber Insider wrote on 4 September that there was no basis for calling the incident ransomware or attributing it to anyone. No group had publicly claimed Dustin in the coverage reviewed for this article by 8 September and CERT-SE has published nothing on it.

Whose 72-Hour Clock Is Running?

For a customer that simply buys hardware from Dustin, the contact and order data Dustin holds is Dustin’s responsibility as controller and the IMY notification is Dustin’s to make. Where Dustin processes personal data on a customer’s behalf, for example under a managed service agreement, it acts as that customer’s processor and Article 33(2) of GDPR requires it to notify the controller without undue delay. In that case the 72-hour clock to IMY belongs to the customer and starts when Dustin tells them, not when Dustin told the stock exchange.

IMY received 12,300 incident notifications in 2025 and says its capacity to supervise them is limited because it prioritises complaints from individuals. A notification is not an investigation. Public-sector buyers have a further question. Dustin holds framework agreements with Kammarkollegiet covering client devices, servers and storage, data centre solutions, AV equipment and software licences. Its own description of those agreements says state agencies place their call-offs through Dustin’s webshop. It also holds Adda’s framework for digital devices for workplaces and schools, one of the routes kommuner use to buy laptops. A webshop outage at Dustin is therefore also a procurement outage for agencies and municipalities in the middle of the autumn term. For entities in scope of Cybersäkerhetslagen (SFS 2025:1506), that kind of supplier dependency sits under NIS2 Article 21.2(d).

Put These Four Questions to Dustin in Writing

  1. Was any data about our organisation or our users held in the support and administration systems the attackers reached? In which of those systems does Dustin act as our processor?
  2. Were customer portal logins, delegated administrator accounts or API keys tied to our account exposed and have they been reset?
  3. Which of our open orders and deliveries are affected and what are the revised dates?
  4. If Dustin provides us with managed services, did the attackers have any access to the tooling used to manage our equipment? What did the forensic review of that tooling find?

Ask by email and keep the replies. If the first answer is yes and Dustin is your processor, your 72 hours start with that email.

The next month settles most of what is open. Dustin says the web and customer portals return later this week. Its IMY notification has to be supplemented as the forensic work identifies the data involved. And Dustin’s financial year closed on 31 August, three days before the intrusion was announced, last year’s fourth-quarter report was published on 8 October. This year’s is where six days without a webshop first gets a figure in kronor.

References

  1. Dustin investigates a serious IT security incident (Dustin Group)
  2. Dustin om it-angreppet: ”Haft möjligheten att själv stänga ner” (EFN)
  3. Dustin probes serious IT security incident (MarketScreener)
  4. Dustin: Inga kunduppgifter ser ut att ha läckt (SweClockers)
  5. Dustin påbörjar återställning efter it-attack (Privata Affärer)
  6. IT online store Dustin takes systems offline after a breach (Techzine)
  7. Ramavtal med Adda (Dustin)

This post is also available in: Svenska

Erik Berg

Erik Berg is CTO and Principal Security Architect at eBuilder Security, with more than a decade in blue team security operations across the private and public sectors, and a focus on emerging threats including the security risks that come with AI.