Cyber Incident Victim: JD Wetherspoon
Timeline
Summary
A UK pub chain experienced a cyberattack compromising personal data of over 650,000 customers, including names, birth dates, contact details, and partial credit card information from approximately 100 cards. The breach occurred via the company's website, affecting customers who interacted with online services such as voucher purchases, newsletter sign-ups, or Wi-Fi registrations. While only the last four digits of credit cards were exposed, the stolen data could potentially facilitate fraud if combined with other personal information. The company notified affected individuals and regulatory authorities, emphasizing the incident was a criminal attack rather than a failure under data protection obligations. No confirmed fraudulent activity linked to the breach had been reported at the time of disclosure.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Between June 15 and June 17, 2015, cyber attackers compromised JD Wetherspoon's website, resulting in unauthorized access to a customer database containing personal information of 656,723 individuals. The breach exposed names, dates of birth, email addresses, and phone numbers. A subset of 100 customers who purchased vouchers online before August 2014 had limited credit card details accessed, though only the last four digits of card numbers were stored in the system. The attack also impacted individuals who signed up for company newsletters, registered for Wi-Fi services through "The Cloud" in JD Wetherspoon establishments, purchased vouchers, or used the website’s contact form. JD Wetherspoon discovered the breach on December 1, 2015, and promptly notified affected customers via email on December 3, 2015. The company acknowledged the stolen data could theoretically facilitate fraud if combined with other leaked information but emphasized no confirmed fraudulent activity had been reported by customers or cybersecurity specialists.

JD Wetherspoon immediately overhauled its website following the attack and reported the incident to the UK Information Commissioner’s Office (ICO), pledging full cooperation with their investigation. CEO John Hutson publicly apologized, stating the breach constituted a "criminal attack" rather than a failure under the UK Data Protection Act, asserting the company had taken reasonable security measures. The delayed public disclosure—nearly six months post-incident—was attributed to the breach’s discovery timeline, though the company emphasized transparency upon confirmation. Jonathan Sander of Lieberman Software noted JD Wetherspoon’s communication strategy mitigated backlash by providing timely updates despite the inherent risks of data exposure. The compromised database’s ultimate disposition remained unknown, as the company could not trace subsequent misuse of the stolen information.
