Close Menu
TechCentralTechCentral

    Subscribe to the newsletter

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News

      Listed: All the MVNOs in South Africa – 2025 edition

      19 June 2025

      TCS | Tech, townships and tenacity: Spar’s plan to win with Spar2U

      19 June 2025

      WhatsApp founders hated ads – Meta is adding them anyway

      19 June 2025

      China’s car factories run cold as price war masks deep overcapacity

      19 June 2025

      Yellow Card, Visa in deal to hasten stablecoin uptake in Africa

      19 June 2025
    • World

      Watch | Starship rocket explodes in setback to Musk’s Mars mission

      19 June 2025

      Trump Mobile dials into politics, profit and patriarchy

      17 June 2025

      Samsung plots health data hub to link users and doctors in real time

      17 June 2025

      Beijing’s chip champions blacklisted by Taiwan

      16 June 2025

      China is behind in AI chips – but for how much longer?

      13 June 2025
    • In-depth

      Meta bets $72-billion on AI – and investors love it

      17 June 2025

      MultiChoice may unbundle SuperSport from DStv

      12 June 2025

      Grok promised bias-free chat. Then came the edits

      2 June 2025

      Digital fortress: We go inside JB5, Teraco’s giant new AI-ready data centre

      30 May 2025

      Sam Altman and Jony Ive’s big bet to out-Apple Apple

      22 May 2025
    • TCS

      TCS+ | AfriGIS’s Helen Hulett on how tech can help resolve South Africa’s water crisis

      18 June 2025

      TechCentral Nexus S0E2: South Africa’s digital battlefield

      16 June 2025

      TechCentral Nexus S0E1: Starlink, BEE and a new leader at Vodacom

      8 June 2025

      TCS+ | The future of mobile money, with MTN’s Kagiso Mothibi

      6 June 2025

      TCS+ | AI is more than hype: Workday execs unpack real human impact

      4 June 2025
    • Opinion

      South Africa pioneered drone laws a decade ago – now it must catch up

      17 June 2025

      AI and the future of ICT distribution

      16 June 2025

      Singapore soared – why can’t we? Lessons South Africa refuses to learn

      13 June 2025

      Beyond the box: why IT distribution depends on real partnerships

      2 June 2025

      South Africa’s next crisis? Being offline in an AI-driven world

      2 June 2025
    • Company Hubs
      • Africa Data Centres
      • AfriGIS
      • Altron Digital Business
      • Altron Document Solutions
      • Altron Group
      • Arctic Wolf
      • AvertITD
      • Braintree
      • CallMiner
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • Domains.co.za
      • ESET
      • Euphoria Telecom
      • Incredible Business
      • iONLINE
      • Iris Network Systems
      • LSD Open
      • NEC XON
      • Network Platforms
      • Next DLP
      • Ovations
      • Paracon
      • Paratus
      • Q-KON
      • SevenC
      • SkyWire
      • Solid8 Technologies
      • Telit Cinterion
      • Tenable
      • Vertiv
      • Videri Digital
      • Wipro
      • Workday
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud services
      • Contact centres and CX
      • Cryptocurrencies
      • Education and skills
      • Electronics and hardware
      • Energy and sustainability
      • Enterprise software
      • Fintech
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Lifestyle
      • Motoring
      • Public sector
      • Retail and e-commerce
      • Science
      • SMEs and start-ups
      • Social media
      • Talent and leadership
      • Telecoms
    • Events
    • Advertise
    TechCentralTechCentral
    Home » Information security » 3.7 million client records compromised in Dis-Chem data ‘incident’

    3.7 million client records compromised in Dis-Chem data ‘incident’

    By Duncan McLeod11 May 2022
    Twitter LinkedIn Facebook WhatsApp Email Telegram Copy Link
    News Alerts
    WhatsApp

    JSE-listed Dis-Chem Pharmacies has disclosed that a data “incident” involving a “third-party service provider or operator” has led to the compromise of millions of client records containing personal information.

    It has not named the third party, but said in a holding statement sent to TechCentral that the company in question had suffered a “suspected cyberattack”. It said no sensitive medical, financial or banking information was contained in the database and that it “immediately took necessary action” and “all possible steps have been taken to isolate the threat”.

    Dis-Chem revealed the incident in a notification published on its website in terms of section 22 of the Protection of Personal Information Act.

    The incident affects almost 3.7 million Dis-Chem customers, with the following information compromised:

    • First names and surnames
    • E-mail addresses
    • Cellphone numbers

    “Based on the categories of personal information impacted, there is a possibility that any impacted personal information may be used by the unauthorised party to commit further criminal activities, such as phishing attacks, e-mail compromises, social engineering and/or impersonation attempts,” Dis-Chem said.

    “For example, it may be cross-referenced with information compromised in other third-party cyber incidents for the further perpetration of crime against data subjects,” it said.

    “Certain personal information was accessed by an unauthorised person on or about 28 April 2022,” the pharmacy group said in the notification. “We have since taken the necessary measures in conjunction with our operator to determine the scope of the compromise and to restore the integrity of our operator’s information system.”

    Certain personal information was accessed by an unauthorised person on or about 28 April 2022

    It said there is “currently no indication that any personal information has been published or misused as a result of the incident”.

    “However, we cannot guarantee that this position will remain the same in future. Therefore, out of an abundance of caution, we are providing information about the incident as well as the remedial action taken to mitigate against any further adverse consequences of the incident.”

    Dis-Chem said it hired the unnamed service provider for “certain managed services”. This third party developed a database for Dis-Chem that contained “certain categories of personal information necessary for the services offered by Dis-Chem”.

    “It was brought to our attention on 1 May 2022 that an unauthorised party had managed to gain access to the contents of the database. Upon being made aware of the incident, we immediately commenced an investigation into the matter and to ensure that the appropriate steps were taken to prevent any further incidents.”

    ‘Additional safeguards’

    Dis-Chem said its third-party service provider has deployed “additional safeguards” to ensure protection and security of information on the database. “These safeguards include, but are not limited to, enhanced access management protocols to the database.

    “We are not aware of any actual misuse or publication of personal information from the personal information that may been acquired. We are however continuing, with the assistance of external specialists, to undertake Web monitoring (including the dark Web) for any publication of personal information relating to the incident.”  — © 2022 NewsCentral Media

    Now read: Dis-Chem gets serious about e-commerce



    Dis-Chem Dis-Chem Pharmacies
    Subscribe to TechCentral Subscribe to TechCentral
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email Copy Link
    Previous ArticleEskom warns winter power outlook is highly uncertain
    Next Article Eskom COO’s urgent plea: stop talking, start building

    Related Posts

    TCS | The Information Regulator bares its teeth – an interview with Pansy Tlakula

    6 October 2023

    Information Regulator pursues Dis-Chem over data breach

    1 September 2023

    TFG snaps up Quench in big e-commerce, logistics push

    2 December 2021
    Company News

    Doing more with less: Altron and Microsoft to show the way forward

    19 June 2025

    Why parents choose CambriLearn for online education

    19 June 2025

    Disrupt first, ask questions later – the uncomfortable truth about incident response

    18 June 2025
    Opinion

    South Africa pioneered drone laws a decade ago – now it must catch up

    17 June 2025

    AI and the future of ICT distribution

    16 June 2025

    Singapore soared – why can’t we? Lessons South Africa refuses to learn

    13 June 2025

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    © 2009 - 2025 NewsCentral Media

    Type above and press Enter to search. Press Esc to cancel.