[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3np1o7icla90n":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":28,"seoTitle":29,"seoTitleEn":30,"seoDescription":29,"seoDescriptionEn":31,"logoUrl":32,"isVerified":4,"isSensitive":4,"isSpamList":33,"isMalware":33,"company":34},"68e3266eda11adda4882524e","jdgroup","JD Group 2023 Data Breach","jd-group","jdgroup.co.za","2023-05-31T00:00:00.000Z","2023-06-05T19:47:51.000Z","2026-07-29T18:46:14.855Z","Company notice and verified breach record","https:\u002F\u002Fmybroadband.co.za\u002Fnews\u002Fsecurity\u002F494239-half-a-million-customers-hit-by-incredible-hifi-corp-and-everyshop-data-breach.html",[15],521878,"known",null,"email_identifiers","High",[23,24,25,26,27],"Email addresses","Government-issued identification numbers","Names","Phone numbers","Physical addresses","\u003Cp>\u003Cstrong>The JD Group 2023 data breach\u003C\u002Fstrong> concerns personal data belonging to customers of the South African retail group's online stores. The company publicly announced the event on May 31, 2023. A verified external breach record reports 521,878 unique email addresses, while the production email-only job processed 464,077 lines and created the same number of unique email associations. These are different scope measures and are not added together.\u003C\u002Fp>\n\n\u003Ch2>How was the event confirmed?\u003C\u002Fh2>\n\u003Cp>Contemporary independent reporting says that two files attributed to JD Group and Everyshop were published on a forum on May 27, that reviewed samples matched South African formats, and that JD Group was contacted. The company statement quoted in the report confirms that a breach occurred; that personal information such as names, contact details, and identification numbers was exposed; that the event was investigated and contained; and that the company would cooperate with regulators.\u003C\u002Fp>\n\u003Cp>The stores on which the company statement appeared are listed as Bradlows, Everyshop, HiFi Corp, Incredible Connection, Rochester, Russells, and Sleepmasters. This identifies affected online assets within the group; it does not establish that every store customer or every account at each brand was affected. The initial access method, actor, and exact access period have not been disclosed in the public sources.\u003C\u002Fp>\n\n\u003Ch2>Which data types are in scope?\u003C\u002Fh2>\n\u003Cp>The verified external corpus contains five structured classes: email addresses, names, phone numbers, physical addresses, and South African government-issued identification numbers. The independent report also mentions additional columns or samples in the two forum files, including dates of birth, gender, and VAT numbers. Those claims are not automatically merged into the five verified classes, and no field should be assumed to be present for every person.\u003C\u002Fp>\n\u003Cp>According to the company statement, banking or financial data was not compromised. Passwords, payment cards, bank accounts, and order contents are also not among the current structured classes. An email match does not prove that all five fields, including an identification number, were present for the same person.\u003C\u002Fp>\n\n\u003Ch2>What do 521,878 and 464,077 represent?\u003C\u002Fh2>\n\u003Cp>The 521,878 value is the number of unique email addresses in the verified external corpus; it is not a customer, person, or source-row count. The local job processed a normalized 464,077-line file created only from the source file's explicit email column and established 464,077 unique email associations. Names, phones, addresses, identification numbers, and all other columns were deliberately excluded from the local import.\u003C\u002Fp>\n\u003Cp>The local email scope is 57,801 below the external measure. That difference does not by itself establish missing people, a different event, or a verification error. Because corpus version, normalization, and deduplication details are not reconciled by the sources, the two values are presented separately.\u003C\u002Fp>\n\n\u003Ch2>What steps can people consider?\u003C\u002Fh2>\n\u003Cp>People who received a notice from the company or a store can rely on the fields named in their own notice. If an identification number or address was involved, new credit or account applications, transaction alerts, and unexpected identity-verification requests can be monitored. A caller should not be trusted merely because they know a South African identification number.\u003C\u002Fp>\n\u003Cp>Instead of following links in unexpected delivery, installment, warranty, refund, or customer-service messages, people should open the relevant store's address directly. One-time codes, passwords, payment details, and identity documents should not be supplied in a suspicious message or call.\u003C\u002Fp>","","JD Group 2023 Data Breach (521.9 Thousand Email Identifiers)","The 2023 JD Group breach contains 521,878 verified unique emails. Review five identity and contact fields and the smaller local email subset.","\u002Fuploads\u002Flogo\u002Fjdgroup_co_za.webp",false,{"name":35,"sector":36,"country":37,"website":10,"websiteArchiveUrl":29,"websiteStatus":38,"websiteCheckedAt":39},"JD Group","Retail","South Africa","active","2026-07-29T18:40:14.000Z"]