Trade & Industry

Pick n Pay customers caught in data breach

Hackers accessed customer information linked to an older version of Pick n Pay's on-demand delivery service during a cyberattack. The incident affected customers who signed up for the service on or before 2022. At the time, the platform operated under the Bottles and later Asap! brands. Pick n Pay started notifying affected customers on 30

Pick n Pay customers caught in data breach

Pick n Pay customers caught in data breach

Share

Hackers accessed customer information linked to an older version of Pick n Pay’s on-demand delivery service during a cyberattack. The incident affected customers who signed up for the service on or before 2022. At the time, the platform operated under the Bottles and later Asap! brands. Pick n Pay started notifying affected customers on 30 May. According to the retailer, the compromised information includes customer names, contact details, delivery addresses and limited payment card information. Pick n Pay started contacting affected customers on 30 May and said the system did not store full card numbers or CVV security codes. As a result, the leaked data cannot be used to make fraudulent card transactions. Some customers, however, remain concerned that criminals could use the exposed personal information in phishing scams or identity theft attempts.

Advertisement

Old platform at the centre of breach

The breach was linked to a previous version of Pick n Pay’s delivery platform, which has since been replaced by a newer system. Although the retailer retired the platform, customer records associated with the service were retained. Those records were later accessed during the cyberattack, drawing attention to the risks organisations face when storing customer information on legacy systems long after they are no longer in active use.

Following the incident, the National Consumer Commission urged affected customers to contact the Information Regulator, which is responsible for enforcing the Protection of Personal Information Act (POPIA). The regulator has also encouraged anyone who believes their personal information may have been unlawfully accessed to lodge a formal complaint.

Pick n Pay said it has notified the Information Regulator and engaged cybersecurity specialists to investigate the breach. The retailer added that it is reviewing its data storage and retention practices as part of its response to the incident.

Trade & IndustryAfrican startups
Vutomi Manzini

Reporting for Business Tech Africa on the funding, tools and strategy shaping the continent's founders and SMEs.

Was this useful?0 reactions
Spiro’s $100 Million Bet Is on Keeping African Riders Moving
Read nextTrade & Industry

Spiro’s $100 Million Bet Is on Keeping African Riders Moving

Spiro has raised $100 million in what is being described as Africa’s largest ever investment in electric mobility. The interesting part is not only the size of the investment. It is where Spiro is putting its money.The company is building around electric motorcycles, but more importantly, it is building the infrastructure needed to keep those

Vutomi Manzini · 3 min readContinue reading