JD Sports data breach hit around 10 million UK customers
- Organization
- JD Sports Fashion plc
- Exploit
- Hacking
- Industry
- Retail
JD Sports Fashion, the UK sportswear and outdoor retailer, disclosed on January 30, 2023 that an intruder had reached a server holding customer information from historic online orders, potentially affecting around 10 million people.
The affected records covered orders placed between November 2018 and October 2020 across the group's brands, including JD, Size?, Millets, Blacks, Scotts and MilletSport. Exposed fields could include customer names, billing and delivery addresses, email addresses, telephone numbers, order details and the final four digits of payment cards. JD Sports said it did not hold full payment card data and had no reason to believe account passwords had been accessed.
The retailer said it identified the unauthorized access and secured the affected server, preventing further attempts, then engaged external cybersecurity specialists and notified the UK Information Commissioner's Office. It began contacting affected customers directly and urged them to be vigilant about scam emails, calls and text messages that might make use of the stolen details.
Chief financial officer Neil Greenhalgh apologized to customers and said protecting their data was an absolute priority for the company. Security commentators questioned why order records more than two years old were still being retained in an accessible system, and noted that under the UK Data Protection Act 2018 the company faced a theoretical maximum penalty of 17.5 million pounds or 4 percent of global annual turnover, whichever was higher.