CSIDB logo
Incident

David Jones

Incident posture

Attack window
Oct 2015
Location
Australia
Status
Historical
CIA posture
Available to members
Updated
2026-01-13 18:19

Linked entities

Victim
David Jones
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2015
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A major Australian retailer experienced a cybersecurity breach where attackers exploited a website vulnerability, compromising customer names, email addresses, and physical addresses. No financial data or passwords were accessed. The company promptly contained the incident, notified affected individuals and authorities, and advised vigilance against unsolicited requests for sensitive information. The national privacy regulator acknowledged a surge in reported breaches and is reviewing the case for potential investigation.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In October 2015, Australian retailer David Jones disclosed a cybersecurity breach involving unauthorized access to its computer systems. The company notified customers via email on the morning of October 2 that attackers had exploited a vulnerability in its website, resulting in the theft of personal customer information. Compromised data included names, email addresses, and physical addresses, though the retailer confirmed no credit card details, financial information, or passwords were accessed. David Jones detected the intrusion shortly before its public disclosure and implemented immediate containment measures to prevent further unauthorized activity. The breach occurred amid heightened cybersecurity concerns in Australia's retail sector, coming just one day after Kmart Australia announced its own customer data theft incident. David Jones declined multiple media interview requests and did not disclose the number of affected customers or the specific timeframe of the intrusion beyond confirming its recent discovery.

The retailer proactively warned customers about potential follow-up attacks using the stolen personal information, advising against sharing financial details via unsolicited phone calls or emails. David Jones formally reported the incident to Australia's Privacy Commissioner as part of mandatory data breach notifications. The Office of the Australian Information Commissioner acknowledged receiving the notification but stated it required further details from David Jones before determining whether to initiate an independent investigation. This incident contributed to a significant increase in reported data breaches during the 2014-15 financial year, as noted by the Privacy Commissioner's office. The company maintained operational continuity throughout the incident while facing public scrutiny over its cybersecurity practices alongside other major retailers experiencing similar breaches during this period.

Sources

Sources available to members: 1 source.

CSIDB