[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2dhse693h2ddd":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":28,"seoTitle":29,"seoTitleEn":30,"seoDescription":29,"seoDescriptionEn":31,"logoUrl":32,"isVerified":4,"isSensitive":33,"isSpamList":33,"isMalware":33,"company":34},"68e3266eda11adda4882524d","JD","JD.com 2013 Data Breach","jd","jd.com","2013-01-01T00:00:00.000Z","2021-06-02T07:06:02.000Z","2026-07-29T18:23:21.781Z","Verified breach record","https:\u002F\u002Ftechnode.com\u002F2016\u002F12\u002F12\u002Fecommerce-giant-jd-apologizes-for-leak-exposing-user-data\u002F",[15,17],"https:\u002F\u002Fmp.weixin.qq.com\u002Fs\u002FKe1I15J384p3NYgO6iejnQ",77449341,"known",null,"email_identifiers","Critical",[24,25,26,27],"Email addresses","Passwords","Phone numbers","Usernames","\u003Cp>\u003Cstrong>The JD.com 2013 data breach\u003C\u002Fstrong> concerns account data from the China-based e-commerce service. A verified external breach record lists the 2013 event, whose exact day is unknown, with 77,449,341 unique email addresses. Contemporary reporting on the company's December 2016 announcement says JD confirmed the leak, attributed it to a 2013 Apache Struts 2 vulnerability, and notified customers considered at risk.\u003C\u002Fp>\n\n\u003Ch2>Which data is in the verified external corpus?\u003C\u002Fh2>\n\u003Cp>The verified record reports four structured classes in 13 GB of data: email addresses, usernames, phone numbers, and SHA-1 password hashes. A SHA-1 value is not a plaintext password, but it is weak by modern password-storage standards, and short or reused passwords remain exposed to offline guessing risk.\u003C\u002Fp>\n\u003Cp>Reporting in 2016 also described broader fields, including QQ accounts and identification numbers, in an approximately 12 GB package then circulating. Because that package size and field scope are not defined as identical to the verified external corpus, those additional claims are not merged into the four structured classes. Payment cards, order history, and bank accounts are not part of the current structured scope either.\u003C\u002Fp>\n\n\u003Ch2>What do the date and 77,449,341 figure mean?\u003C\u002Fh2>\n\u003Cp>Because the sources do not disclose the exact breach day, the January 1, 2013 date field is only a year-level placeholder; it does not establish that the event occurred on January 1. December 2016 is the period of the company statement and reporting about the data package offered for sale, not a separate breach date.\u003C\u002Fp>\n\u003Cp>The 77,449,341 value represents unique email addresses in the verified external corpus. It is not the same measure as accounts, people, or total source-file rows. Production has no JD import job or locally indexed email, password, phone, or username corpus, so the value is not presented as a local total.\u003C\u002Fp>\n\n\u003Ch2>How was the source chain established?\u003C\u002Fh2>\n\u003Cp>The verified breach record supplies the exact email count, four fields, and SHA-1 detail. TechNode's December 12, 2016 report links to the company's official WeChat announcement and reports JD's confirmation of the 2013 event. Another secondary page formerly linked by the verified record now returns 404 and is therefore not used as a public source.\u003C\u002Fp>\n\n\u003Ch2>What can users do about account risk?\u003C\u002Fh2>\n\u003Cp>If a password used with JD.com in 2013 was also used for another service, it should be replaced there with a unique password, and multi-factor authentication should be enabled where available. Instead of following links in unexpected delivery, refund, promotion, or password-reset messages, users should open JD's address directly.\u003C\u002Fp>\n\u003Cp>An email match does not prove that a password was plaintext, an account was taken over, or payment and order data was exposed. The verified boundary of this record is the email, username, phone, and SHA-1 password-hash fields in the external corpus.\u003C\u002Fp>","","JD.com 2013 Data Breach (77.4 Million Email Identifiers)","The 2013 JD.com breach contains 77,449,341 verified unique emails. Review four account fields, SHA-1 password hashes, and the 2016 notice.","\u002Fuploads\u002Flogo\u002Fjd_com.webp",false,{"name":35,"sector":36,"country":37,"website":10,"websiteArchiveUrl":29,"websiteStatus":38,"websiteCheckedAt":39},"JD.com, Inc.","E-Commerce","China","active","2026-07-29T18:14:28.000Z"]