Pick n Pay customers caught in data breach
Hackers accessed customer information linked to an older version of Pick n Pay's on-demand delivery service during a cyberattack. The incident affected customers who signed up for the service on or before 2022. At the time, the platform operated under the Bottles and later Asap! brands. Pick n Pay started notifying affected customers on 30

Pick n Pay customers caught in data breach
Hackers accessed customer information linked to an older version of Pick n Pay’s on-demand delivery service during a cyberattack. The incident affected customers who signed up for the service on or before 2022. At the time, the platform operated under the Bottles and later Asap! brands. Pick n Pay started notifying affected customers on 30 May. According to the retailer, the compromised information includes customer names, contact details, delivery addresses and limited payment card information. Pick n Pay started contacting affected customers on 30 May and said the system did not store full card numbers or CVV security codes. As a result, the leaked data cannot be used to make fraudulent card transactions. Some customers, however, remain concerned that criminals could use the exposed personal information in phishing scams or identity theft attempts.
Old platform at the centre of breach
The breach was linked to a previous version of Pick n Pay’s delivery platform, which has since been replaced by a newer system. Although the retailer retired the platform, customer records associated with the service were retained. Those records were later accessed during the cyberattack, drawing attention to the risks organisations face when storing customer information on legacy systems long after they are no longer in active use.
Following the incident, the National Consumer Commission urged affected customers to contact the Information Regulator, which is responsible for enforcing the Protection of Personal Information Act (POPIA). The regulator has also encouraged anyone who believes their personal information may have been unlawfully accessed to lodge a formal complaint.
Pick n Pay said it has notified the Information Regulator and engaged cybersecurity specialists to investigate the breach. The retailer added that it is reviewing its data storage and retention practices as part of its response to the incident.



