Data breach
JD
- Records
- 141,631,698
- Breach date
- 1 January 2013Estimated
- Added
- 4 February 2025
What was exposed
3 types of data · 2 more reported
- Usernames141,630,235
- Email addresses96,787,970
- Phone numbers68,733,386
- PasswordsReported, not counted
- Government IDsReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In 2013, the Chinese e-commerce company JD, then known as Jingdong, suffered a major data breach after attackers exploited a security flaw in Apache Struts 2, a widely used web application framework. Data tied to the breach resurfaced in December 2016, when a large package of user records began circulating on underground Chinese forums and black markets. According to our investigation team, this listing contains more than 141.6 million records, including over 141.6 million usernames, roughly 96.8 million email addresses, and about 68.7 million phone numbers. JD acknowledged the leak in a public statement and linked it to the 2013 vulnerability, saying it had fixed the flaw and alerted affected users at the time.
Breach Timeline
December 10, 2016: Chinese media reported that a 12 GB data package containing tens of millions of records was being sold on black markets, with sellers claiming the data came from JD. Reported prices ranged from 100,000 to 700,000 RMB, and industry sources said the data had already been resold many times.
December 11, 2016: JD issued an official statement, carried by CCTV, saying the data originated from a 2013 Struts 2 security vulnerability. The company said it had quickly repaired its systems and prompted at-risk users to upgrade their account security, though it acknowledged a small portion of users had not done so and remained at risk.
December 12, 2016: TechNode reported that JD had apologized for the leak and was urging users to set stronger, regularly changed passwords. The company also said it was working with authorities.
What Information Was Compromised?
Our analysis found the following data types in this breach: usernames, email addresses, and phone numbers.
JD's December 2016 statement and subsequent reporting indicate the circulating package also included passwords, QQ account identifiers, and Chinese national ID numbers. According to our investigation team, usernames appear in nearly every record, while email addresses and phone numbers are present in a smaller share of the dataset.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The combination of usernames, passwords, and email addresses carries the most direct risk. If passwords were reused on other sites, criminals can attempt credential stuffing, automatically trying leaked email and password pairs across banking, email, and shopping services until one works. Chinese media coverage of the 2016 resale noted that stolen data is often used this way.
Phone numbers and ID numbers enable more targeted scams. Fraudsters can pose as bank staff, delivery companies, or JD customer service, using real details such as a person's name or phone number to appear credible. This type of deception has been tied to financial losses among Chinese consumers in reporting around the leak.
What Is JD Doing in Response?
In its December 11, 2016 statement, JD said its security team had determined the data stemmed from the 2013 Struts 2 flaw, which it said affected nearly all Chinese internet companies as well as many banks and government agencies. The company said it completed system repairs quickly after the vulnerability emerged and prompted users at risk to upgrade their account security. It added that most affected users had done so, but a small portion had not and still faced some risk.
JD also said it had established a long-term cooperation mechanism with police to combat hackers who attack accounts and sell user data, and it urged customers to use unique, complex passwords on e-commerce and payment platforms, enable phone verification, and keep login and payment passwords separate and strong.
What Should You Do If You Were Affected?
Change your JD password immediately, and change it anywhere else you reused it. Reused passwords are the main way leaks turn into account takeovers.
Use a long, unique password for each account, ideally with a password manager, and enable two-factor authentication where it is offered.
Be skeptical of unexpected calls, texts, or emails claiming to be from JD, banks, or delivery services, especially if the caller references details about you. Never share verification codes or payment passwords.
Watch your financial accounts for unfamiliar activity, and consider reviewing your statements for small charges you might otherwise miss.
