A cyber attack has compromised UK fashion retailer JD Sports, along with a number of its associated brands (such as Millets, Blacks and Size?). This attack is unique in that the customer data stolen appear to be fairly old, however; the information was taken from online purchases made between November 2018 and October 2020.
The compromised customer data did not include full payment information, but did include the last four digits of cards in addition to names, billing and delivery addresses, phone numbers, and order details. There is probably no immediate risk of fraud, but the Information Commissioner’s Office (ICO) is warning impacted customers to expect scam attempts that make use of the stolen information.
Limited customer data stolen from old online orders
The full list of brands impacted by the cyber attack includes JD, Size?, Millets, Blacks, Scotts and MilletSport. In total about 10 million records of customer data were thought to be taken in the attack. JD Sports says that it is continuing to investigate the incident in conjunction with ICO. Ransomware does not appear to be involved at this point, and the impacted companies have not lost any of their regular function.
Though the cyber attack appears to be recent, only customer data from over two years ago appears to have been accessed. It is not year clear exactly how that happened. The incident has raised some questions about exactly how and why the company was storing order details that apparently went back as far as four and a half years.
JD Sports does not have anything to share with the public on this point as of yet, but some independent cybersecurity research indicates that the breach may have originated from a misconfigured internet-facing database that was found in the middle of 2022 (as Chris Denbigh-White, Security Strategist at Next DLP, observes): “Often in situations like this the headline will read something like ‘Hacker Exposes millions of users’ personal and sensitive data’ yet rarely does the headline read ‘Misconfiguration of company datastore leads to data being ‘copied and pasted’.’ According to the security researcher @0xyzqt, a JD Sports database containing customer information was identified as exposed directly to the internet as early as July 2022.”
“Recent high-profile fines handed out for GDPR non-compliance are a stark reminder that GDPR regulations apply to this kind of data. This requires companies to maintain continuous visibility to sensitive data and ensure that security controls are in place to protect that data from loss or misuse,” noted Denbigh-White.
The information about this breach, reported in early December 2022, lines up with what JD Sports has confirmed was leaked in the cyber attack. It is possible that attackers spotted the same thing the researcher did via tools such as Shodan, before JD Sports reacted and fixed the error, and seized on the opportunity to exfiltrate this massive amount of customer data.
Cyber attack may cool JD’s momentum
JD Sports is a well-regarded fashion brand in the UK that has seen consistent and strong growth since 2011, with significant year-over-year leaps in revenue starting in 2018. The company idled between 2020 and 2021 due to the pandemic slowdown, but rocketed to a record value of £8.56 billion in 2022 and projects more growth in 2023 (to include reaching £1 billion in profits for the first time).
The company does not have much of a history of cyber attacks prior to this; most of its prior legal issues in the UK have centered on competition law and mergers. That makes its handling of this current incident worthy of note, and thus far there is at least some reason to question if the company covered the incident for an extended period after it stemmed from an unprotected database that was not properly disclosed.
In the meantime, JD Sports has not issued any special advice to those impacted by the stolen customer data other than to be wary of scam and phishing attempts that may make use of it to forge communications that could be legitimate-looking at first glance. Though the company says that user credentials were not compromised in the incident, it may be prudent to reset passwords on the impacted sites and check for any re-use of those login credentials in other places. Initial breach notifications are often revised some weeks or months later to reveal that the scope of the stolen information was greater than initially reported.
Retail in general has been in a challenging period in terms of cyber attacks, with Sophos reporting that over 75% were targeted by ransomware attempts at some point in 2021. Cyber attacks on retail are almost always financially motivated, and the attackers are seeking to exfiltrate customer data; it is impossible to trust that any ransom or payment agreement will be honored if the attackers capture full payment data or something equally valuable.
There is also reason for all types of UK businesses to be on higher alert as of late, as the country appears to be experiencing a rash of cyber attacks that mirrors the one Australia went through in late 2022 (one of the countries that JD Sports also has a presence in). Since 2023 began there have been ransomware attacks on Royal Mail and the UK branch of fast food giant Yum! Brands; the Royal Mail attack was so damaging that it has disrupted mail service throughout January. And just prior to the turn of the new year, The Guardian also experienced an attack in which customer data was stolen.
Lior Yaari, CEO and co-founder of Grip Security, thinks that the conditions merit a stronger response from JD Sports, or any other retailer that might suffer a similar compromise of customer data: “Retailers should approach a breach of customer data similar to an internal breach of employees -requiring every customer to reset their account credentials. Rather than sending an email asking them to do this, it would be better to force a reset with at least two factor authentication or some sort of secondary verification. The official announcement form JD and the news coverage sets the stage for the hackers to start sending out password reset phishing emails to the 10 million customers to harvest their credentials. Disclosing the breach is the right thing to do and necessary, but it can also help the hackers by priming the customers for a password reset email that will trick them into divulging their passwords and payment information. There is likely to be additional fallout from this breach that will play out in the future.”

