← Blog

Pick n Pay Data Breaches: Full Timeline Through 2026

Share on X

People search Pick n Pay data breach timeline because millions of customers entrust payment and identity data to everyday transactions. BreachHistory indexes 1 Pick n Pay-linked incident (1 company-confirmed). This page maps every attested event through 2026 with internal links to canonical records.

Why Pick n Pay breach history matters

Pick n Pay operates in Retail (South Africa). Across indexed rows, recurring themes include mixed intrusion and disclosure events. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.

Full timeline through 2026

2026 — legacy Bottles/Asap! app breach; Capitec urges card replacement

Verified breach. Verified incident — March–July 2026 reporting window. Pick n Pay online executive Enrico Ferigolli confirmed a data breach involving customer information from a legacy on-demand platform first known as Bottles and later Pick n Pay Asap!, affecting users who registered before 2022 on a system since overhauled in 2025. Exposed fields include names, email addresses, phone numbers, delivery addresses, encrypted passwords, credit card type, last four digits, and expiry dates; Pick n Pay states full card numbers and vali Exposed categories include Per Pick n Pay: names, emails, phone numbers, delivery addresses, encrypted passwords, credit card type, last four digits, and expiry dates—not full PANs or valid CVV codes; Capite. No attested victim count is published for this row yet. See the pick-n-pay-asap 2026 record and canonical BreachHistory entry.

Patterns and analysis

  • Mixed intrusion and disclosure events — appears across multiple Pick n Pay catalog entries; prioritize controls that address this class of failure.
  • Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
  • 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.

What to do if you may be affected

  1. Step 1: Enable phishing-resistant MFA on every account tied to this brand.
  2. Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
  3. Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
  4. Step 4: Use virtual card numbers for online checkout where your bank supports it.
  5. Step 5: Bookmark the Pick n Pay company page for new 2026+ disclosures.

Canonical BreachHistory hub

Explore every indexed row: breachhistory.com/pick-n-pay · Latest: pick-n-pay-asap2026.

Sources: BreachHistory catalog (1 row for Pick n Pay), company and regulator disclosures cited in individual breach records.