JD Group 2023.0 Data Breach

JD Group South African Multi-Brand Retailer Breach (2023): 522K Customer Records Including Government ID Exposed | ObscureIQ
ObscureIQ Breach Intelligence

Classification Tags

RetailEmail AddressFull NameGovernment IDPhone NumberPhysical Address
Moderate SeverityWebsite / service breach

JD Group South African Multi-Brand Retailer Breach (2023): 522K Customer Records Including Government ID Exposed

South African retailer operating furniture, appliance, and electronics brands.

Verified by ObscureIQ Intelligence
38/100Breach Risk Index
30Data Value
10Market Recency
1129dSince Breach

Breach Intelligence Summary

Entity: JD Group · Actor: Unknown · Sources: 3 references
Attack: Unknown
Profile: Company · Retail and consumer goods distribution · Multi-brand retail group · South Africa
Timeline: Breach (2023-05-31) · Indexed (Jun 05, 2023) · Year (2023.0)
Exposure: 522K records · 5 fields: Email Address, Full Name, Government ID, Phone Number, Physical Address
Status: Confirmed

Executive Summary

In May 2023, South African retailer JD Group announced a data breach affecting several of its online brands (Bradlows, Everyshop, HiFi Corp, Incredible, Rochester, Russells, Sleepmasters), exposing over 520,000 customer records including names, email and physical addresses, phone numbers, and South African ID numbers.

ObscureIQ assessment: Exposure enables phishing, order fraud, account abuse, and delivery impersonation. Retail data can also reveal household composition, spending patterns, and consumer vulnerability.

Breach Impact

South African ID numbers combined with names, addresses, and phone numbers create identity-fraud risk beyond typical contact exposure.

About JD Group

JD Group is a South African furniture and appliance retail group operating brands such as Bradlows, HiFi Corp, Incredible, Russells, and Sleepmasters.

Why They Hold Your Data

Multi-brand retail groups collect customer identity, contact details, addresses, payment-adjacent records, order history, loyalty data, and financing or account information across retail operations.

Data Points Exposed

5 verified field types
Email Address
Full Name High
Government ID Critical
Phone Number
Physical Address High

Field names are shown in full for clarity and search visibility. Canonical machine keys are emitted only in this page’s structured data.

Exploitation & Downstream Threats

Threat Activity:Moderate
Primary downstream threats:
  • Identity theft and synthetic identity construction using government-issued IDs
  • SIM swap attacks where phone numbers are present
  • Targeted phishing campaigns using exposed email addresses
  • Doxxing risk from physical address exposure
Threat vectors:
  • Phishing, credential stuffing & account takeover
  • Name-based social engineering
  • Identity fraud with official bodies
  • SIM swapping, vishing & SMS phishing
  • Physical stalking, mail fraud & identity verification

Recommended Actions

If you believe your information may be included:

Protect Your ID Documents
Government-ID exposure enables document fraud — monitor and report misuse.
Enable MFA Everywhere
Turn on multi-factor authentication on email first, then financial accounts.
Report & Recover
If you spot misuse, start an official recovery plan and report fraud.

Frequently Asked Questions

What happened in the JD Group breach?

In May 2023, South African retailer JD Group announced a data breach affecting several of its online brands (Bradlows, Everyshop, HiFi Corp, Incredible, Rochester, Russells, Sleepmasters), exposing over 520,000 customer records including names, email and physical addresses, phone numbers, and South…

What data was exposed?

Verified fields include Email Address, Full Name, Government ID, Phone Number, Physical Address.

What should I do if I was affected?

Change reused passwords, enable MFA, and (if identity or financial data is involved) freeze your credit and monitor your accounts.

Sources & References

Every claim on this page is traceable. This breach draws on:

Breach Index
Have I Been Pwned
Record & field corroboration
Cross-source
LeakCheck.io
Independent catalogue listing
ObscureIQ Intelligence
ObscureIQ proprietary analysis
Risk Index scoring & downstream-threat assessment

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation