JD Sports says 10 million customers hit by cyber attack (Includes orders placed for the JD, Size?, Millets, Blacks, Scotts and MilletSport)

Posted 30th Jan 2023
Huge data breach, after the JD Group was hit by a cyber attack., information below. Funnily enough, i've been getting recent calls, quite an increase actually on scammers trying to say they're from Amazon, BT, Natwest, Vodafone, Paypal & more.



Sportswear chain JD Sports has said stored data relating to 10 million customers might be at risk after it was hit by a cyber attack.

The company said information that "may have been accessed" by hackers included names, addresses, email accounts, phone numbers, order details and the final four digits of bank cards.

The data related to online orders between November 2018 and October 2020.

JD Sports said it was contacting affected customers.



The group said the affected data was "limited". It added it did not hold full payment card details and did not believe that account passwords were accessed by the hackers.

"We want to apologise to those customers who may have been affected by this incident," said Neil Greenhalgh, chief financial officer of JD Sports. "Protecting the data of our customers is an absolute priority for JD."

The attack related to online orders placed for the JD, Size?, Millets, Blacks, Scotts and MilletSport brands and it is understood it was detected by the company in recent days, but only the historical data was accessed.

The company said it was working with "leading cyber security experts" and was engaging with the UK's Information Commissioner's Office in response to the incident.

Mr Greenhalgh said affected customers were being advised "to be vigilant about potential scam e-mails, calls and texts".

4078123_1.jpg


Email being sent out states:


Dear Customer,

We wish to inform you about a security incident involving the data of some customers of JD Group brands who placed orders with us between November 2018 and October 2020. Our records show that you may be affected.
The affected data is limited.

We do not hold full payment card details and we do not believe account passwords were accessed.
However, we want to advise our customers to be vigilant for scam emails, calls and texts.
We take the protection of customer data extremely seriously and we are sorry this has happened.

What happened?

We were the target of an attack that has resulted in unauthorised access to a system that contained historic customer data relating to some online orders placed between November 2018 and October 2020. Our security team responded quickly and there has been no subsequent unauthorised access to this server. We are engaging with the relevant authorities as necessary.

What information is involved?

Only limited information was held on this database consisting of full name, delivery and billing address(es), email address, phone number, final 4 digits (only) of payment card and/or order details.

What you can do

While you do not need to take any specific action, please remain vigilant to fraud attempts and be alert for any suspicious emails, calls or texts which say they are from JD Sports or any of our Group brands. Avoid clicking on links in any unexpected emails or texts.
You can also find helpful information about protecting yourself from phishing scams at the National Cyber Security Centre at ncsc.gov.uk/collection/phishing-scams/spot-scams. If you want to report any suspicious activity to law enforcement, please contact Action Fraud (the UK’s National Fraud and Cyber Crime Reporting Centre) at actionfraud.police.uk.

Please do not reply to this email. If you would like to contact us about this matter, you can email us at Privacy.Support@jdplc.com.



4078123_1.jpg

How can i help potect myself?


  • Look out for any weird texts claiming to be from the likes of JD/ JDGroup, also any strange emails from those pretending be be from your bank and strange delivery links asking for further information. If you are unsure, ring the bank or the retailler DIRECTLY, they then should confirm if a scam or not.

  • Be careful about giving personal information away - Some scammers try to get your personal information – for example, the name of your primary school or your National Insurance number. They can use this information to hack your accounts. If you come across sites that ask for this type of information without an obvious reason, check they’re legitimate.



Community Updates
New Comment

100 Comments

sorted by
's avatar
  1. Ravsterocks's avatar
    Ravsterocks
    Sue JD Sports. Let’s get that compensation paid.
  2. miffyl's avatar
    miffyl
    is it only those subsidiaries that you mentioned as the group is pretty big and includes companies such as Go Outdoors as Ultimate Outdoors:
    Aktiesport
    Blacks
    Bodytone
    Chausport
    Down Town Locker Room
    Exercise4Less
    Finish Line, Inc.
    Fishing Republic
    Footpatrol
    Get The Label
    GO Outdoors
    JD Gyms
    JD Sports
    Mainline
    Millets
    Nice Kicks
    Perry Sport
    Scotts
    Shoe Palace
    Size?
    Sportzone
    Sprinter
    Tessuti
    Tiso
    The Hip Store
    Ultimate Outdoors

  3. whatyadoin's avatar
    whatyadoin
    Half arsed apology , hopefully a class action will ensue , their group IT systems are terrible , I never get emails for orders / dispatches , spoke to them multiple times and still not fixed
    Sieja's avatar
    Sieja
    stop buying from this shop, if all we will start acting like that, they gonna feel forced to make changes. They should pay compensation for every single person!
  4. M4tt31's avatar
    M4tt31
    "Only limited information was held on this database consisting of full name, delivery and billing address(es), email address, phone number, final 4 digits (only) of payment card and/or order details."

    Whats their definition of limited? Surely thats everything a customer provided minus the whole card number.
    BodisBest's avatar
    BodisBest
    I thought that, short of your first pet name and NI, is there anything else
  5. JustaSingh's avatar
    JustaSingh
    Having worked in IT, the only ones that take this stuff seriously (re. Spending money on security) are those in 'regulated'.industries..i.e banks, insurance. No system is perfect, so it's down to you take sensible precautions .

    Btw staff in firms look at your details all day long,. your data is at risk from internal and external forces.

    Take some precautions yourself...i.e use an alias email account like duckduckgo's one..simple to set up and you can still use your usual email provider.

    Don't forget the hackers aren't looking for tech savvy folks details, they are aiming to IID the easy targets.
    xanoas's avatar
    xanoas
    Those industries only care because the FCA is always on them about it.
  6. RomeoAlphaKilo's avatar
    RomeoAlphaKilo
    For any retail sites (except Amazon) use a Permanent Junk email address, different SIM (if it requires a phone number). fake birthdate, temp credit card. And use a password manager like Bitwarden. Your real email address should only be used for banks, credit cards, NHS details etc. Everything else use a email address that you'll keep only for retail or junk mail. I know when theres a breach, because i get a load of junk mail in my inbox. Talking about a security incident and protecting your details three years after the fact is pointless. Your real ID and online ID is important, as more and more essential services go online. Have the sense to create a secondary email and associated details to shop around. None of these places need your birthdate. I've gone so far as to create seconday facebook account and twitter account for apps that require me to log on with those details.
  7. you_gotta_be_kidding's avatar
    you_gotta_be_kidding
    The wording is awful, "10 Million customers hit by cyber attack" They're wording it like they've attacked us individually to take away the blame from their own IT insuecurities.
  8. Gollywood's avatar
    Gollywood
    So they contacted customers 5 years after the 1st breach.

    Thanks JD
    SoCal's avatar
    SoCal
    Hackers managed to get into the database that old orders were held.. not that they have been hacking for the last 5 years.
    Every company has to hold info for at least 6 years, so these hackers got into this area of the business.
  9. Sandmannn's avatar
    Sandmannn
    That is why I use temporary email address, and phone numbers and virtual bank card number.
    Yas_Min's avatar
    Yas_Min
    Use a different name for every website too and keep a spreadsheet so you know which website compromised you
  10. Ade_king's avatar
    Ade_king
    Most UK companies dont have IT teams, they spend cheap and expect wonderful IT.
    thewindburner's avatar
    thewindburner
    worked in IT can confirm, most management only care when things go wrong, not bothered that investing some cash could have stopped the thing going wrong!


    Edit: that's why when stuff like this happens I hate seeing the IT teams taking the brunt of the flack! (edited)
  11. HotAddict's avatar
    HotAddict
    Getting really fed up with all these data breaches, there needs to be serious repercussions for companies that don't invest in securing their IT systems. (edited)
    SoCal's avatar
    SoCal
    No one is ever 100% secure.
    There is even software that can hack any phone.. even if you have never received a text or email.
  12. Elijah_Malachi's avatar
    Elijah_Malachi
    They simply sold your data. No hack occurred 
    BodisBest's avatar
    BodisBest
    Hardly
  13. DealioSmith's avatar
    DealioSmith
    Have had an increase in spam calls and mails lately. Looks like ANYTHING you ever submit online eventually ends up on a list
    MadeDixonsCry's avatar
    MadeDixonsCry
    Exactly.

    If I can help it, I always use fake details. Why should company xyz have my real DOB?
  14. Solee's avatar
    Solee
    Gee, I wonder which group located in which country could possibly be behind this. (edited)
    Bread's avatar
    Bread
    JD Group...United Kingdom😁
  15. robmk's avatar
    robmk
    Normally would not care, but i'm still smarting from those puma trainers on Boxing day so... (edited)
  16. Mentos's avatar
    Mentos
    Oh dear god, people will know I shop at JD sports
  17. paz_coutinho's avatar
    paz_coutinho
    Having worked with them, their IT infrastructure is so far behind its crazy.
    snappyfish's avatar
    snappyfish
    Amazing.
  18. spankwilder's avatar
    spankwilder
    Millets took two weeks to despatch a tent. Flipping freezing I was!
    arachnoid's avatar
    arachnoid
    So not really an intents time
  19. MusicmanJP's avatar
    MusicmanJP
    The real cost of outsourcing
  20. Thumbnail's avatar
    Thumbnail
    Do these companies ever face any consequences?
    JonCollett's avatar
    JonCollett
    Seemingly not. All of the time there are few consequences, the companies involved will do little about it, because it costs them little or nothing.

    If we had a regulator that said if you allow a data breach as the company that allowed it, you have to pay a fine of (say) £500 per person by way of compensation for every name, I'd bet that they'd tighten up on security then.

    And it would go some way towards compensating all of the inconvenience that they have caused for a lot of people.


  21. Ravsterocks's avatar
    Ravsterocks
    Increased spam emails after order pma ex with JD sports that they did not honor and cancelled and refunded without explaining.
    Sick of JD sports treating customers this way. Pack up and go bust JD sports.
  22. LeePaulBaxter's avatar
    LeePaulBaxter
    Received the email

    Worded badly but then it is JD. Worded as if saying the breach was 2018-2020 not that it's data from that period

    After just eat managed to not keep my details safe and I got bit by fraudulent activity I keep my card frozen for online purchases now using the NatWest app


    JD are pathetic they can't even have an online stock system that's accurate (edited)
    richpriest's avatar
    richpriest
    Hi, I'm from NatWest, can you confirm your date of birth please?
  23. Kako_Ponga's avatar
    Kako_Ponga
    I'm working as IT and the JD team is really nice but the heads are really dumb, like the think is living in 2000 not 2023, even my I get a month ago 1k accounts hacked from his systems but most of them from another website as dominos pizza and more, but even Microsoft have issues that should be fixed 8 years ago, the IT world is really big and per day more, for example try it Intelx.io and use the domain of your company, you will see as JD have nice protection
    Yas_Min's avatar
    Yas_Min
    Websites are protected well enough nowadays. But their backups may have been found by just port scanning at random
  24. dodgymix's avatar
    dodgymix
    Jd / size websites are terrible

    The only way I can ever order anything is via klarna or clear pay

    I never receive order emails but they show in my account and I only know items been shipped when I get an evri email

    Terrible company
  25. sillybillysara's avatar
    sillybillysara
    Is that why every time I tried to pay on the app it said ‘fraud’ as it failed payment.?
  26. harmony999's avatar
    harmony999
    I would never buy anything from JD Sports as they treat their staff like suspected criminals.
  27. couponchaser's avatar
    couponchaser
    I don't understand why would they want to store order details for 2 years. Personal information should be deleted or anonymised after 6 months.
  28. Marky264's avatar
    Marky264
    Currently going through a data breach case with a law firm for the DivideBuy mess. Its finally going to settlement stage soon. If they decline a settlement for me then it'll be going to court proceedings. After seeing this I may decide to look into it against JD.
  29. orlovekat's avatar
    orlovekat
    Can you get any compensation?
    Any no win no fee lawyers for instant money?
  30. Dominatez's avatar
    Dominatez
    Now I wonder what exploit they used to get into the system.
    Solee's avatar
    Solee
    Normally it's 1st line staff opening attachments or some rudementary foothold.
  31. sr_387's avatar
    sr_387
    what was taken exactly just email address? got alot of spam there this month more than usual but just report fishing on outlook and its cut it down
    Kako_Ponga's avatar
    Kako_Ponga
    You can check in haveibeenpwned.com is your emails is compromised, but to know the exactly you need to pay heheh
  32. wakeeleffendi's avatar
    wakeeleffendi
    Not by cyber attack
    They were hit by JD sport 😡😡
  33. bryanhaines399's avatar
    bryanhaines399
    So they have our details because of those £12 puma mirage trainers which almost nobody got. I was already annoyed that they were sending spam because of that.

    Edit: oh never mind, it was older data. (edited)
  34. CD2DD's avatar
    CD2DD
    Own by Mark the cheat!!! No surprise he doesn't give Dawn to British people. Think about his shameless no refund policy..I.e. Once you buy from them than they can only refund you in their own credit means that cheater will have your money whichever way you go. So don't think about any hack but deliberate money earning trick. Anyways none care about consumer. Government will fine him if not at worst and that is it. Never compensated consumers.
  35. jokerevo's avatar
    jokerevo
    so why report this 3 years late????
  36. hd1944's avatar
    hd1944
    youtube.com/wat…1m4

    It was only a small breach just all your details... They really care about data privacy it seems.
  37. RealDonaldTrump's avatar
    RealDonaldTrump
    Another excuse to lose my 3rd parcel in the warehouse.
  38. greenflower123's avatar
    greenflower123
    Is this another Mike Ashley chaos?
  39. JoeKing5321's avatar
    JoeKing5321
    Definitely had an increase in spam as of late creeping in to main inbox. 
  40. mad.dog's avatar
    mad.dog
    Well I got an email from them yesterday it seems

    It landed in my gmail spam as it was written in Portuguese!?!?!

    The sender address looks suspect, news@email-jdsports.com, but I cannot see any phishing links in the email so no idea what is going on
's avatar
Discussions
Top Merchants