When people hear the term data breach, the first question is usually:   “Were payment details stolen?”

But as a recent incident involving fashion retailer Zara shows, the answer doesn’t always need to be “yes” for there to be real risk.

What Happened?

Zara recently confirmed that a data breach exposed information belonging to around 197,000 customers. The breach was linked to a third-party customer service platform, rather than Zara’s core systems.

The information involved included:

  • Names
  • Email addresses
  • Phone numbers
  • Shipping details

Importantly, Zara has stated there’s no evidence that payment card details or passwords were compromised.

So… no financial data. No passwords. Sounds less serious, right?

Not quite.

Why This Still Matters

Even without financial information, this type of data is extremely valuable to attackers.

Think about it from a cybercriminal’s perspective. They now potentially have:

  • Real customer names
  • Verified email addresses
  • Accurate contact details
  • Purchase or delivery context

That’s everything needed to create convincing, highly targeted phishing emails or messages.

For example:

“Hi John, we noticed an issue with your recent Zara order. Please click here to update your delivery details…”

Because the message feels personalised and comes from a trusted brand, people are far more likely to click.

And that’s where the real danger lies.

The Growing Risk of Third-Party Platforms

One of the most important takeaways from this breach isn’t just the data itself—it’s where the breach originated.

It didn’t happen directly inside Zara’s systems.

It came through a third-party provider.

This is becoming increasingly common.

Modern businesses rely on a wide range of external platforms for:

  • Customer service
  • Marketing automation
  • Analytics
  • Payment processing
  • Support systems

Each one of these integrations adds convenience… but also adds risk.

In simple terms, every connection is another potential entry point.

Why Trust Is Still on the Line

Even if no bank details are exposed, incidents like this can still damage customer trust.

From a customer’s point of view:

  • Their personal information has been exposed
  • The breach is linked to a brand they trust
  • They may now become targets for scams

That erosion of trust can be just as damaging as financial loss—sometimes more so.

What Businesses Should Really Be Thinking About

This type of incident highlights a shift in how organisations need to think about security.

It’s no longer just about protecting your own systems.

It’s about understanding:

  • Who has access to your data
  • Where that data is stored and processed
  • How secure your third-party providers really are

In other words, your security posture is only as strong as your weakest link—and that link is often outside your direct control.

The Bigger Picture

At Lithium Systems, this is something we’re seeing more and more with clients.

Traditional security controls (firewalls, antivirus, patching) are still critical—but they’re no longer enough on their own.

There’s an increasing need to focus on:

  • Vendor risk management
  • Data access visibility
  • Third-party security reviews
  • Clear accountability for data handling

Because attackers are adapting—and they’re actively looking for the easiest way in.

The Takeaway

You don’t need financial data for a breach to cause real damage.

Personal information like names, emails, and contact details is often more than enough to fuel targeted scams and long-term risk.

The key question for business leaders is:

How much of your customer data is currently accessible through third-party platforms?

Because for many organisations, that’s where the real exposure now sits.

At Lithium Systems, we help businesses:

  • Identify where sensitive data is stored and shared
  • Review third-party risks and vendor access
  • Highlight gaps before attackers do
  • Put practical controls in place to reduce exposure


Speak to us to book a security review and get a clear picture of your current risk position—plus straightforward, actionable steps to improve it.

Each asset has an associated cost, and you want to maximize any investment by ensuring that equipment is being used properly by the right people. Asset management is also a key component of overall risk management as it ensures that your business only uses supported and compliant devices.

Single Order Generic Ethernet Access, or SOGEA for short, is a type of broadband internet connection that provides a dedicated Ethernet connection directly from a customer’s premises to the internet service provider’s (ISP) network.

SOGEA allows customers to connect to the internet using only a single order, which includes both the broadband service and the telephone line rental. This means that customers can use the same telephone line for both voice calls and internet access, without the need for a separate Openreach phone line.

One of the benefits of SOGEA is that it can provide a faster and more reliable connection than traditional broadband options such as ADSL, which rely on copper telephone lines. SOGEA is also a good option for customers who don’t need a traditional phone service, but still require high-speed internet access.

SOGEA is currently available in the United Kingdom, and it’s expected to become a more widely used broadband option as more internet service providers adopt it.

Starlink internet is a revolutionary new way to connect to the internet that is fast, reliable, and available virtually anywhere in the world.

With Starlink, you can say goodbye to slow, unreliable internet connections and hello to high-speed internet that delivers download speeds of up to 100 Mbps. Best of all, Starlink uses advanced satellite technology to provide internet access to areas that are traditionally underserved or completely without internet access. Whether you’re living in a rural area, traveling on the road, or just tired of slow internet speeds, Starlink has the solution you’ve been looking for.

Our leased line product is a dedicated, private telecommunications circuit that provides a direct and continuous connection between two points, typically used for internet access, voice communications, or data transfer.

One of the main benefits of a leased line is the reliability and consistency it offers, as it guarantees a fixed bandwidth and symmetric upload and download speeds, without sharing with other users. This makes it ideal for businesses that require high levels of connectivity and bandwidth, such as those that use cloud services or require large file transfers. Additionally, our leased lines offer improved security, as they are not vulnerable to interference or hacking from external sources, unlike shared broadband connections. Lastly, leased our lines come with a service level agreements (SLAs), which provide guarantees for uptime and response times, ensuring a high level of customer service and support.

Ethernet First Mile (EFM) is a technology that enables high-speed, dedicated internet access over traditional copper-based infrastructure. Specifically, EFM refers to the use of Ethernet technology to provide connectivity from a customer’s premises to the service provider’s network.

In traditional broadband access, a customer’s connection to the provider’s network typically involves a shared medium such as cable or DSL. With EFM, the customer’s connection is dedicated, meaning that they have a direct, uncontended connection to the provider’s network.

EFM is often used to provide high-speed internet access to small and medium-sized businesses, as well as remote or underserved areas. It can offer speeds of up to 35 Mbps over distances of up to 10 kilometers, depending on the quality of the copper infrastructure.

Overall, EFM is a cost-effective solution for businesses that require reliable, high-speed internet connectivity but cannot access fiber-based solutions due to geographical or economic limitations.

FTTC stands for Fiber to the Cabinet, which is a type of internet broadband technology. It involves running a high-speed fiber optic cable from the internet service provider (ISP) to a street cabinet, which is usually located on the side of a road or a pavement, and then using the existing copper telephone lines to connect homes and businesses to the cabinet.

The distance between the cabinet and the property can affect the speed of the internet connection. The closer the property is to the cabinet, the faster the internet speed.

FTTC can provide faster internet speeds compared to ADSL (Asymmetric Digital Subscriber Line) technology, which uses copper telephone lines for both download and upload data. FTTC can offer download speeds of up to 80 Mbps (megabits per second) and upload speeds of up to 20 Mbps, depending on the quality of the copper telephone lines and the distance between the property and the cabinet.

FTTC is often used as an interim solution while ISPs work on providing full fiber connections to homes and businesses.