JD Sports Fashion PLC (LSE:JD.) has become the latest company to be targeted by cybercriminals following recent attacks on the Royal Mail and the Guardian amongst others.
The FTSE 100 listed retailer said the incident resulted in unauthorised access to a system that contained customer data relating to some online orders placed between November 2018 and October 2020.
The affected JD Sports group brands are JD, Size?, Millets, Blacks, Scotts and MilletSport, the company said in a statement.
The affected data is limited, JD added, noting it does not hold full payment card data and it has no reason to believe that account passwords were accessed.
The company said the information that may have been accessed consists of the name, billing address, delivery address, email address, phone number, order details and the final four digits of payment cards of around 10mln customers.
“We have taken the necessary immediate steps to investigate and respond to the incident, including working with leading cyber security experts” JD said.
“We are engaging with the relevant authorities, including the UK's Information Commissioner's Office (ICO), as necessary” it added.
Chief financial officer Neil Greenhalgh said: "We want to apologise to those customers who may have been affected by this incident."
Shares were trading flat at 161.8p.
A bit more detail
Whether or not the sports retailer fell victim to a ransomware attack is unconfirmed, adds Leo Grieco, but leaked data is often the punishment if ransomware operators' demands aren’t met.
Matt Hull, head of threat intelligence at NCC Group, said “In 2022 we saw big insurers like Medi bank compromised by ransomware.”
Companies like Royal Mail and the Guardian fell victim to ransomware attacks, as the number of strikes rose by 2% in December.
However, these are not the actions of lone hackers or online anarchists, but rather organisations offering “ransomware as a service (RaaS)” for a paid fee.
Matt Hull stated: “The way the ransomware business model works is you have the ransomware operators that develops the type of ransomware. And then you've got access brokers who hack into the organisation.
“Once they've hacked in, they then sell that access to the highest bidding ransomware gang.”
Ransomware operators such as Blackcat, Lockbit and Conti have built successful businesses around RaaS.
Some of these gangs offer customer service through support clients, pay people to get their logos tattooed and are even leaked talking about hitting Christmas targets, Hull added.
-- updated for ransomware detail --