{"id":428332,"date":"2021-12-29T07:00:36","date_gmt":"2021-12-29T05:00:36","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=428332"},"modified":"2021-12-29T07:03:18","modified_gmt":"2021-12-29T05:03:18","slug":"pick-n-pay-customer-data-exposed-online","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/428332-pick-n-pay-customer-data-exposed-online.html","title":{"rendered":"Pick n Pay customer data exposed online"},"content":{"rendered":"<p>Several Pick n Pay customers who used the company&#8217;s delivery service have had their data exposed online, a tip from a MyBroadband reader has revealed.<\/p>\n<p>Customer delivery information for Pick n Pay&#8217;s online shopping service was available on a tracking website for courier Dawn Wing to anyone on the Internet who knew where to look.<\/p>\n<p>The site exposed people&#8217;s names and addresses, and included photos of their orders taken by couriers to prove that they had delivered the items.<\/p>\n<p>Order tracking pages also included photos of the driver and the driver&#8217;s vehicle, together with their licence plate number.<\/p>\n<p>This data was exposed because Dawn Wing and Pick n Pay used sequential order numbers in the URL to allow customers to track their deliveries.<\/p>\n<p>They then failed to require a login to access this data.<\/p>\n<p>Anyone who knew the format of the tracking URL could add or subtract 1 from their order number to view the details of someone else&#8217;s order.<\/p>\n<p>If you remove the tracking ID from the URL, the site directs you to a login form, but this authentication system did not protect the actual tracking data.<\/p>\n<p>MyBroadband contacted Pick n Pay and Dawn Wing to notify the companies of the data leak and requested comment.<\/p>\n<p>Neither had responded at the time of writing, but the issue appears to be resolved. Visiting an order tracking link now takes you to a blank page.<\/p>\n<div id=\"attachment_428444\" style=\"width: 810px\" class=\"wp-caption aligncenter\"><a  data-lightbox=\"post-image\" href=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/12\/Pick-n-Pay-Dawn-Wing-security-vulnerability.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-428444\" class=\"size-full wp-image-428444\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/12\/Pick-n-Pay-Dawn-Wing-security-vulnerability.jpg\" alt=\"\" width=\"800\" height=\"2226\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/12\/Pick-n-Pay-Dawn-Wing-security-vulnerability.jpg 800w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/12\/Pick-n-Pay-Dawn-Wing-security-vulnerability-144x400.jpg 144w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/12\/Pick-n-Pay-Dawn-Wing-security-vulnerability-155x430.jpg 155w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/12\/Pick-n-Pay-Dawn-Wing-security-vulnerability-768x2137.jpg 768w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/12\/Pick-n-Pay-Dawn-Wing-security-vulnerability-552x1536.jpg 552w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/12\/Pick-n-Pay-Dawn-Wing-security-vulnerability-736x2048.jpg 736w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/a><p id=\"caption-attachment-428444\" class=\"wp-caption-text\">Redacted screenshot illustrating a privacy flaw in the Pick n Pay \/ Dawn Wing delivery tracking site<\/p><\/div>\n<hr \/>\n<h3 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/security\/428222-waspa-website-hacked-tue-1600.html\" rel=\"bookmark\">WASPA website hacked<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>The personal data of Pick n Pay customers who used the company&#8217;s delivery service has been exposed online.<\/p>\n","protected":false},"author":341039,"featured_media":373113,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[50043,35,5380],"class_list":["post-428332","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-data-leak","tag-headline","tag-pick-n-pay"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/428332"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341039"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=428332"}],"version-history":[{"count":2,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/428332\/revisions"}],"predecessor-version":[{"id":428454,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/428332\/revisions\/428454"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/373113"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=428332"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=428332"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=428332"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}