Hackers gained access to a database that contained private information about more than 650,000 customers of a chain of British pubs, according to a posting on its website.
JD Wetherspoon reported that about 100 of its customers had the last four digits of their credit and debit card numbers stolen through a breach of the company’s former website. Because the complete numbers hadn’t been stored, the company said no stolen data could be used for fraud.
The website posting indicated the database contained information like email addresses, names, birthdays and phone numbers of 656,723 people. The pub chain’s CEO, John Hutson, said in the posting that neither its customers nor its cyber security specialists gave any indication that anyone had used that stolen customer information for fraud, “although we cannot be certain.”
Hutson said in the posting there were no passwords stored in the database. He asked customers to watch out for suspicious emails, such as ones that ask recipients to respond with personal or financial information or to click on links. Such emails are commonly seen in phishing schemes.
The breach took place in June, the company said in the website posting. The pub chain only learned of the breach last week, and subsequently began investigating and notifying customers.
Huston said in the website posting that JD Wetherspoon has “taken all necessary measures to secure” its website following the breach (the pub chain has since switched to a new website manager that it says has no ties to the hack) and that a forensic investigation is ongoing. The pub chain has also notified the British authority that regulates data protection of the breach.
As of Monday morning, it’s still not known who was responsible for the hack.
The news comes just days after digital toy manufacturer VTech announced that the personal data of millions of its customers was hacked, including some photographs of children. VTech has said it’s cooperating with law enforcement officials from around the world to investigate.