South Africa’s largest supermarket retailer is the latest major brand to face the uncomfortable reality that old data does not simply go away.
Pick n Pay this week confirmed a data breach involving customer records from its former on-demand delivery platform, originally known as Bottles and later rebranded as Pick n Pay asap!. The affected records date from 2022. The platform itself was decommissioned in 2025. Pick n Pay became aware of the incident after customer data was reportedly spotted being offered for sale on the dark web, with threat actors claiming to have listed it as far back as 23 March 2026.
The company has apologised, launched a forensic investigation with an independent cybersecurity firm, and notified the Information Regulator.
What Was Exposed
The breach is significant in scope. According to Pick n Pay, the compromised dataset includes customer names, contact details, dates of birth, delivery addresses, Smart Shopper numbers where linked, encrypted passwords, and partial payment card information including card type, the last four digits, and expiry dates.
Pick n Pay has been clear that full card numbers and CVVs were never stored on the system, meaning direct card fraud is unlikely from this dataset alone. Threat actors selling the data have claimed otherwise, but the company’s online executive Enrico Ferigolli confirmed that while the data structure included a CVV field, no data was ever stored in it.
That is an important distinction. But it does not make the exposed information harmless.
The Real Threat: Phishing and Social Engineering
Pick n Pay itself has warned customers plainly: the combination of personal details in this dataset is precisely what criminals need to run convincing phishing and social engineering attacks.
A fraudster armed with your name, delivery address, birth date, partial card details, and the knowledge that you used a specific app has everything needed to impersonate your bank or Pick n Pay itself. They can call you by name, reference your card ending in a specific four digits, mention your home address, and manufacture urgency around a supposed fraudulent transaction.
That kind of targeted, personalised scam is far more convincing than generic phishing. And South African consumers, already navigating a high volume of fraud attempts, now face a more credible version of it.
The Legacy Data Problem
What makes this breach particularly instructive for other organisations is the timeline. The data is from 2022. The platform was shut down in 2025. The breach surfaced publicly in 2026.
This is the legacy data problem in plain view. Systems get decommissioned. Platforms get replaced. But the data those systems held does not always receive the same attention during wind-down. If historical records are not properly deleted, anonymised, or secured at the point of decommissioning, they remain a liability long after the product is gone.
For any South African organisation that has migrated platforms, rebranded apps, or wound down legacy systems in recent years, this incident raises a direct question: what happened to the data those old systems held?
What Pick n Pay Got Right, and What the Industry Should Learn
Pick n Pay’s response has been measured. The company notified customers proactively, engaged the regulator, appointed an independent forensic investigator, and was transparent about what was and was not in the dataset. That is broadly in line with what good breach response looks like under POPIA.
But the deeper lesson here is not about response. It is about retention.
South African organisations are required under the Protection of Personal Information Act to retain personal data only for as long as it is necessary for the purpose for which it was collected. Legacy platforms holding years-old customer records without a clear retention and deletion policy represent a compliance gap that is also a security gap.
Attackers do not discriminate between active and decommissioned systems. If the data exists and is accessible, it is a target.
For Affected Customers
If you had an account on the Bottles or Pick n Pay asap! platform prior to or during 2022, treat the following as practical steps, not optional precautions:
- Change your password on any service where you used the same credentials
- Be suspicious of any call, message, or email that references your personal details, even if it sounds legitimate
- Do not share OTPs or banking credentials in response to inbound contact, regardless of how credible the caller sounds
- Monitor your accounts for unusual activity
The data is out there. Awareness is your best defence right now.

