[ad_1]
British sports apparel chain JD Sports is warning customers of a data breach after its servers containing online ordering information for 10 million customers were hacked.
In a data breach notice shared by affected customers, the company warned that an “attack” exposed customer information for orders placed between November 2018 and October 2020. .
JD Sports said it detected the unauthorized access immediately, took swift action to secure the compromised server, and prevented further access attempts.
However, hackers were able to steal the data of approximately 10 million unique customers, which consists of:
- full name
- payment details
- Shipping address
- e-mail address
- telephone number
- Order details
- Last 4 digits of payment card
This data may be used to launch phishing or social engineering attacks against exposed individuals.
“We are actively contacting affected customers to advise them to be aware of the risks of fraud and phishing attacks,” reads the incident report.
“This includes paying attention to suspicious or unusual communications purporting to be from JD Sports or our group brands.”
According to JD Sports, all payment card details for online orders are not stored, so it is unlikely that full financial information was leaked. The same applies to account passwords, which the company says has no reason to believe it has been accessed.
The company notified authorities about the security incident, filed a notice on the London Stock Exchange portal, and the security incident also affected its sub-brands JD, Size?, Millets, Blacks, Scotts and MilletSport. I explained.
Some notification destinations Asked JD Sports’ decision to keep historical records of online orders that were fulfilled more than four years ago increased the likelihood of a data breach.
“Hi, I received this email today. 1) Why are you storing data for orders that are nearly 5 years old? 2) Basically everything (circled) “Limited data “am. ” commented on the customer See the data breach notice above on Twitter.
If you have a JD Sports account, we recommend that you use extreme caution to reset your password.
Additionally, if you may be using the same credentials on other online platforms, reset your password there as well and replace it with a strong, unique password.
Finally, beware of targeted phishing emails that can use this stolen data to steal more information from your customers.
[ad_2]
Source link