ransomware Credible South Africa (ZA) retail

Pick n Pay listed by the APT73 ransomware group

Pick n Pay

📅 09 January 2025
CompanyPick n Pay
Domainpnp.co.za
CountrySouth Africa (ZA)
Sectorretail
Breach date2025-01-09
People affected250,000
Ransomware groupapt73
Data typescustomer data, corporate records, financial information

Overview

The APT73 ransomware group has listed Pick n Pay Group Ltd, a major South African retailer operating the Pick n Pay and Boxer brands, on its leak site. The listing appeared on 9 January 2025.

What was published

The group claims to have exfiltrated data from the retailer. The archive is expected to include customer records, corporate documentation and financial information.

Risks for affected individuals

  • Customer personal data may be exposed.
  • Financial records could enable fraud.
  • Employees' information may be included.

What remains unknown

  • The volume of data exfiltrated.
  • Whether the data has been published.
  • The response status of the company.

What affected people should do

Customers should monitor their accounts and be cautious of unsolicited communications. Pick n Pay should notify affected customers and staff, review compromised systems, and coordinate with South African authorities on the response.

Pick n Pay leak listing

Sources

  • http://basherq53eniermxovo3bkduw5qqq5bkqcml3qictfmamgvmzovykyqd.onion/page_company.php?id=111