Britain’s JD Sports says customer data accessed by cyberattack, IT Security News, ET CISO
British sports and fashion retailer JD Sports Fashion has been the victim of a cyberattack which saw customer data relating to historical online orders compromised, it said on Monday.
The group said the affected data was “limited”, as it does not hold full payment card data and did not believe account passwords were accessed.
The attack related to online orders placed for the JD, Size?, Millets, Blacks, Scotts and MilletSport brands between November 2018 and October 2020.
JD Sports said information that may have been accessed consisted of the name, billing address, delivery address, email address, phone number, order details and the final four digits of payment cards of about 10 million customers.
The group apologised to customers and is contacting those affected to advise them to be vigilant to the risk of fraud and phishing attacks. It is also investigating the incident, working with cybersecurity experts and engaging with the UK’s Information Commissioner’s Office (ICO), the country’s data protection watchdog.
Cyberattacks on UK companies are becoming increasingly common.
Earlier this month the Royal Mail’s export services were severely disrupted by what it described as a cyber incident.