JD Sports, a well-known British sportswear chain, has issued a warning about a data breach that affected 10 million customers who placed orders on its website. A hacker broke into its server and gained access to customers' online order information.

In notifications sent to customers affected by the breach, the company said the attack exposed customer data from orders placed between November 2018 and October 2020.
JD Sports acted quickly and decisively when it discovered unauthorized access to its servers, taking steps to immediately stop any further intrusion attempts.
See also: QNAP fixes critical vulnerability affecting NAS devices
Nevertheless, the attackers managed to gain access to data of 10 million customers which included:
- Full name
- Phone number
- Email address
- Delivery address
- Order Details
- Billing details
- Last four digits of payment card
This data could be used to carry out phishing or social engineering against JD Sports customers.
“ We are proactively contacting customers to advise them to be vigilant about the risk of fraud and phishing attacks ,” the incident report states
“This includes being on the lookout for any suspicious or unusual communications purporting to come from JD Sports or any of our group brands“.
JD Sports has clearly stated that it does not store full payment card details, meaning that no full financial data. Furthermore, the company claims that there is no indication that account passwords were accessed.
See also: Over 422 million people fell victim to data breaches in 2022
The company says it has notified authorities of the breach of its customer data and filed a notice on the London Stock Exchange portal, explaining that the security incident also affected the company's sub-brands JD, Size?, Millets, Blacks, Scotts and MilletSport.
"We would like to apologise to those customers who may have been affected by this incident," said Neil Greenhalgh, JD Sports' chief financial officer. "We advise them to be vigilant about potential emails , calls and messages and provide details on how to report them."

“ We are continuing a full Protecting review our customers’ data is an absolute priority for JD of our cybersecurity in collaboration with external experts following this incident ,” Greenhalgh said. “ .”
Some affected customers complained about JD Sports' decision to retain a history of online orders made four years ago, increasing the chances of more data being stolen.
See also: US No Fly list shared on hacking forum
“Hi, I received this email today. 1) Why are you storing order data from almost 5 years ago and 2) “restricted data” which is basically everything,” one customer commented on Twitter, referring to the data breach notification.
Customers with JD Sports accounts should reset their passwords. Additionally, if the same passwords are used on other online platforms, they should be changed there as well, as attackers could compromise those accounts.
Finally, as JD Sports suggested, customers affected by this data breach should be on the lookout for messages or phishing emails that may use this stolen data to steal further information.
Data breaches are an increasingly common security threat that all businesses need to be prepared for. By understanding what a data breach is and why it poses such a risk to companies large and small, we can better prepare for this modern security risk. Investing in strong cybersecurity solutions and training staff in safe online practices are key steps to protecting data.
Source: www.bleepingcomputer.com
