JD Sports admits intruder accessed 10 million customers' data
- Reference: 1675091220
- News link: https://www.theregister.co.uk/2023/01/30/jd_sports_breach/
- Source link:
In a post to [1]investors this morning , the London Stock Exchange-listed business said the intrusion related to infrastructure that housed data for online orders from sub-brands including JD, Size? Millets, Blacks, Scotts and MilletSport between November 2018 and October 2020.
The data accessed consisted of customer name, billing address, delivery address, phone number, order details and the final four digits of payment cards "of approximately 10 million unique customers."
[2]
The company does "not hold full payment card details" and said that it has "no reason to believe that account passwords were accessed."
[3]
[4]
As is customary in such incidents, JD Sports has contacted the relevant authorities such as the Information Commissioner's Office and says it has enlisted the help of "leading cyber security experts."
The chain has stores across Europe, with some operating in North America and Canada. It also operates some footwear brands including Go Outdoors and Shoe Palace.
[5]Crims steal data on 40 million T-Mobile US customers
[6]PayPal says crooks poked around 35,000 accounts in credential stuffing attack
[7]Mailchimp 'fesses up to second digital burglary in five months
[8]The Guardian ransomware attack hits week two as staff told to work from home
"We want to apologize to those customers who may have been affected by this incident," said Neil Greenhalgh, chief financial officer at JD Sports. "We are advising them to be vigilant about potential scam emails, calls and texts and providing details on now to report these."
He added: "We are continuing with a full review of our cyber security in partnership with external specialists following this incident. Protecting that data of our customers is an absolute priority for JS."
[9]
We asked JD how the intruder was able to gain entry, how long they were inside and whether they've had contact with the perpetrators. The retailer has written to customers but the letters, seen by us, contain pretty much the same information that was posted to investors.
A spokesperson at the ICO told us: "We have been made aware of a cyber incident involving the retailer JD Sports and we are assessing the information provided."
John Davis, UK and Ireland director for the SANS Institute, reckons cybercriminals are "leveling up" and their "attacks are more prevalent, more sophisticated and harder to detect."
[10]
"Brand reputations and relationships with customers are on the line," he added. "Customers will reward businesses who can persuade them they are best equipped to manage their data." ®
Get our [11]Tech Resources
[1] https://www.londonstockexchange.com/news-article/JD./cyber-security-incident-regarding-historic-orders/15815662
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y9f3rPfMfAlIQFE32a05AAAAAAo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y9f3rPfMfAlIQFE32a05AAAAAAo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y9f3rPfMfAlIQFE32a05AAAAAAo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2023/01/20/t_mobile_us_data_breach/
[6] https://www.theregister.com/2023/01/19/paypal_data_breach/
[7] https://www.theregister.com/2023/01/19/mailchimp_fesses_up_to_2nd/
[8] https://www.theregister.com/2023/01/04/guardian_ransomware_attack/
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y9f3rPfMfAlIQFE32a05AAAAAAo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y9f3rPfMfAlIQFE32a05AAAAAAo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[11] https://whitepapers.theregister.com/
Nope. They take security EXTREMELY seriously.
As always. As do all the others, like BA or TalkTalk.
So no reason at all to worry.
Hackers take security EXTREMELY seriously because you can make a lot of money from it, but if you are the company boss then your first thought might be that security is expensive... so being hacked might save you money. I'm not gaslighting, it's just that the modern data environment prioritizes access everywhere, security is just a "feature" these days.
has enlisted the help of "leading cyber security experts."
How 'bout doing that BEFORE you're hacked? Doesn't this imply you weren't taking due care?
All lies
There is also this https://www.reddit.com/r/DevelEire/comments/zjw07x/jd_sports_data_from_15_million_users_leaked/
Not a "hack". The usual unprotected bucket. Totally liable.
Had An E-Mail from JD Sports..... in Portuguese
Nothing from JD sports for 7 years, then suddenly an e-mail from them in Portuguese.
The web addresses of inbuilt links point to the UK website, and the translation of the text (some, i did not select all) indicates it is about a security breach.
Haven't a clue why it is in Portuguese.
Re: Had An E-Mail from JD Sports..... in Portuguese
Haven't a clue why it is in Portuguese.
Security, how many Chinese super ninja cyber warriors speak Portuguese? Taps side of nose, knowingly
Re: Had An E-Mail from JD Sports..... in Portuguese
Wasn't Macau a Portuguese colony? Perhaps it's still spoken there, as in Goa?
JD
I am sick and tired of recruiters asking "do you want to see JD?"
Why would I want to? Duh...
" Protecting that data of our customers is an absolute priority for JS "
Bullshit.