We have had a data breach involving customer information from 2022 linked to an older version of our on-demand platform, first known as Bottles and later as Pick n Pay asap!, which has since been replaced. The current Pick n Pay asap! + Smart Shopper platform is a completely separate system that launched last year, which customers had to re-register for, and is not affected by this incident.
We became aware yesterday that customer data linked to the historical Bottles platform was allegedly being offered for sale on the dark web.
We immediately initiated a forensic investigation with an independent cybersecurity firm. All appropriate processes were and are being followed, including notifying the Information Regulator.
The exact number of affected customers is unknown, but as a precautionary measure, we have notified all customers who were registered on the Bottles platform at the end of 2022.
Customer information on the current Pick n Pay application remains secure. asap! operates on a new and separate infrastructure from the decommissioned infrastructure, and as part of this, we have already completely overhauled our approach to data security. We continue to review our architecture and security measures, including how we manage and retain historical customer data, expand monitoring, and invest in the latest security technology.
The leaked data from 2022 data may include customer names, usernames, email addresses, mobile numbers, dates of birth, delivery addresses, Smart Shopper numbers where linked, and encrypted passwords. It also includes the type of credit card, the last four digits of the credit card number and an expiry date. It does NOT include full credit card numbers or CVV security codes as Pick n Pay does not store these details. Full payment card data is managed by accredited payment security providers in line with strict industry standards and compliance requirements, supported by regular independent audits. Without these full details, the credit card cannot be used to directly process fraudulent card transactions. South African ID numbers were also not stored on the Bottles platform.
As you would expect, we are taking this extremely seriously, and our immediate priority is ensuring customers have clear information about what has happened, what it means for them in practical terms, what we are doing about it, and how they can protect themselves.
At this stage, the forensic investigation is ongoing and we are still working to determine the source but there is no evidence of unauthorised access to the decommissioned platform.
While the data involved is more than four years old and some customer details may no longer be current, we strongly advise customers to remain vigilant against unsolicited calls, messages or emails, avoid sharing passwords or one-time PINs, and change passwords on any other platforms where the same credentials may have been used.
We'd like to assure you that no full payment card information was exposed, and the data cannot be used to directly process fraudulent card transactions. But other personal data from four years ago was indeed exposed, and for that we are truly sorry.
We are working closely with cybersecurity specialists and undertaking a broader review of historical data management and retention practices as part of our ongoing investment in customer data security.
We promise to keep our customers updated.
Enrico Ferigolli, Executive Online at Pick n Pay