You Should Care About What Supermarkets Know About You
I’m not sure about the rest of the world, but in the last few years there’s been a new trend with supermarket loyalty cards having “exclusive discounts” for members, a step up from their previous main offering of gathering points to receive discounts. This new trend particularly irritates me as it makes signing up for their membership pretty much a necessity to not be ripped off, with the non-membership price being sky high but the membership price being comparible to other supermarkets without a similar scheme. A lot of people defend this because “who cares if they know how often I buy toothpaste” which I think is a very surface level way of looking at it.
I’m not sure if this quote is attributable to someone, but “It’s not if, but when” referring to a data breach should be considered. You need to think about what happens if all of that data from your supermarket of choice ends up in the hands of someone who wants to use it for ill intent.
So now some criminals know you like to buy a sweet treat as part of your shop. Who cares?
First, why do supermarkets want this data in the first place? You as an individual data point probably aren’t much use to them, but as an aggregate across their whole customer base they can analyse shopping trends to know which products to stock and where to offer promotions, how successful those promotions are. They can look at peak and lull shopping times to manage shop floor stock levels, and when good times for restocking are. If you visit multiple stores for different products, they could optimise this experience. These scheme also usually come with their own app where they can try to influence purchase for specific products using product spotlighting or even less obvious things like a recipe section.1
So all of that power now falls into the hands of criminals. The difference now is that you’ve been singled out. They care about you as an individual data point.
Since you provide your name and address to sign up, we can assume that the criminals know who you are and where you live, and they’ve identified you as someone who they can reach as a potential target. To start with, they know which supermarket you shop at. This may seem innocuous, but in the UK there’s stereotypes of the customers of different supermarkets. Depending on what your attack is, you might prefer a Waitrose shopper over a Lidl shopper for example. It could also indicate that you prefer a different supermarket over the one that’s closest or easiest to get to, which may indicate that you are in line with that supermarkets stereotypical shopper.
So they know where you go, but when do you go? If you have a routine where you go shopping at 10am every Saturday, then it’s unlikely that you’re all of a sudden going to break from that routine, so now we know when your house is going to be potentially empty. That may matter depending on the attack. Do they want your house empty? Do they want to target you directly? What about if you’re in a rush going out of the door where you might be easier to catch off guard? The same applies if you visit a different branch of that supermarket for lunch whilst you’re at work. That can be used to give a rough estimate of where you work which can then be used to predict when you’d be leaving your house for work in the morning. Maybe that recent purchase of sun cream and travel shampoo is a clue that you’re going on holiday soon, so your home will be empty for a while.
Now they know when your house is potentially empty, let’s add a bit more confidence to that. If your weekly shop is 7 microwave meals, a loaf of bread and some ham then it’s highly likely that you’re shopping for one person2. Are you buying things like nappies and baby food? Are you buying school uniform from the clothing section? What you’re buying and how much you’re buying gives a good indication of what the household looks like which in turn can be used for specific attacks and scams.
The specific items you buy could also make you more of a target. I’ll take Pokemon cards as an example since they have a hot reseller market. If you have a purchase history of Pokemon cards then what are the odds you have some valuable cards in your possession? What about video game purchases? Televisions? Supermarkets sell a lot of high value goods on top of groceries which may be of interest to criminals and also help pinpoint your income bracket.
I’ve laid these points out in a way that makes burglary seem like the main way leaked supermarket data can be exploited, but there’s a number of other more subtle things that can be done. Spear phishing is another fairly obvious one, if you’ve recently made a big purchase, an email about activating its warranty from “the supermarket” won’t be too unexpected. Other social engineering based activities can be used. As mentioned earlier, if the attacker knows you’re going to be rushing out of the door to get to work, they could use that state of mind to their advantage.
The information could also be used to target an individual instead of property. If you can determine if members of a household fit your demographic and can estimate what their movements are, it makes it easier to target them, whether that’s scams, stalking, or something more sinister. The trend in purchase history could also be revealing. If your spend is gradually decreasing over time it could indicate financial hardship, making you a candidate for types of coercion and exploitation. It works the other way as well. If your spend increases, especially in regards to luxuries, it could indicate that things are going well for you in your work life, so you similarly could make a good target for coercion into more white collar crimes.
These attacks could become more sophisticated with more data sets. Again, “it’s not if, but when.” So add in data leaks from petrol stations, so where you’re driving to and how often can be calculated. Dating apps for an array of coercion and blackmail. Memberships to gyms, clubs and hobbies to more accurately pinpoint your movements. Employment history, banking information, utilities usage. The more of this data that can be joined together about you, the more information that can be derived about you, making the attacks against you become more sophisticated. This is without bringing any of the data motherloads from the big tech companies into the equation.
With the proliferation of vibe coding, you’ve got to be even more careful who you hand your data to. Just because they’re a well known company doesn’t mean they’re not feeding your data to AI agents and relying on it to implement secure coding and production environments. Conversely, AI will probably make it easier for criminals to utilise large amounts of data to their advantage.
I know it makes me sound like a doomer, assuming the worst case scenario, but even when a company can take all of the right steps to protect your data and still lose it, the only real thing I can do as an end user it to reduce my surface of attack. Supermarkets gating 60% discounts on toothpaste really make that difficult.
1 There’s probably more they could do here. It’s not something I have experience with so I’m not sure exactly what they do with the data, so this is speculation.
2 They could be in a HMO, have housemates etc. but this could potentially be worked out by looking at the HMO register or seeing if there’s multiple accounts at the same address in your leaked database - both aren’t guarantees though!