Shoprite Names Cybersecurity Its Top Risk as Data Breaches Rise to Four in a Year

By

October 10, 2026

Shoprite has rated the controls that protect it from cyberattacks and data breaches as only “partially effective”, according to TechCentral. This is the weakest rating the retailer gives to any of its six main business risks.

The rating appears in the group’s 2026 integrated report. The report puts information security, including cyber risk, at the top of its list of main risks.

Shoprite recorded four data breaches in FY2026. This was up from three in FY2025 and one in FY2024. All four breaches involved personal information, and 44 customers were affected.

In FY2025, only one customer was affected. In FY2024, a single breach affected 1 437 customers. The report does not describe what happened in any of the incidents.

The rise in breaches goes against the group’s own target. Shoprite’s risk register sets “zero tolerance for security breaches and unmitigated critical vulnerabilities” for this risk.

Shoprite rated the basic level of this risk as critical. Even after its controls are counted, the remaining risk is still rated medium.

The other five main risks all have controls rated at least “substantially effective”. All five are left with a low remaining risk.

These five risks are technology systems going down, problems at distribution centres and in logistics, and breaking laws or rules. Stock losses and weak controls over financial reporting complete the list.

The report said AI tools and smarter cybercrime make more frequent and more serious attacks more likely. It said a breach could expose sensitive data or business secrets and badly disrupt operations.

The group holds a large amount of customer data. Its Xtra Savings loyalty programme records more than 2 500 card swipes a minute. The programme accounts for more than 88.7% of sales.

Shoprite said it holds more than 5 000 data points for each loyalty member. Its Money Market Account has more than 4.3 million customers. Its Sixty60 delivery service made R25.5-billion in sales in FY2026.

The risk of key technology systems going down is also rated critical. Causes include supplier failures, internet and cloud outages, crashed servers and telecoms problems.

For this risk, Shoprite aims for 99% system availability during trading hours and 95% outside them. It rates those controls as substantially effective.

Shoprite has also changed how it manages risk. It merged its risk, compliance, insurance, information security and health and safety teams into one department.

That department now reports to a chief risk and compliance officer. In the 2025 report, a group risk manager ran the risk function, and information security was listed separately.

The report names “cybersecurity posture hardening” as one of the main focus areas of the year. It said AI makes cyber threats worse but also offers tools to spot and stop them faster.

The board’s audit and risk committee is chaired by Linda de Beer. It lists information security and cyber defence among its priorities for FY2027, along with rules for the group’s use of AI.

Chief technology officer Chris Shortt is in charge of all the group’s information and technology assets. He told TechCentral’s Meet the CIO podcast that cybersecurity is the one area that keeps him awake at night.

Group CEO Pieter Engelbrecht wrote that Shoprite is upgrading to SAP S/4Hana in its finance, data analytics and people teams. The project is set to be finished in 2029.

Source: this article is based on reporting by TechCentral. Image: TechCentral. Written with the help of AI and published by the Tzaneen Voice Technology desk. See our Editorial Standards.