Aussie hair and beauty brand admits customer data breached in hack | Nine.com.au

August 20, 2026 2 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: nine.com.au

Threat Risk: Medium
Victim: Oz Hair and Beauty
Incident: Unauthorized access to an online purchase and order platform.
Impact: Exposure of customer names, email addresses, phone numbers, and purchase history.
Attacker: Unidentified threat actors
Analysis: Attackers gained unauthorized access to the brand’s online ordering platform, compromising PII including contact info and purchase histories. While financial data remained secure, the exposure of contact details significantly increases the risk of targeted phishing and social engineering attacks against the customer base.
Recommendations: Implement stricter data retention policies to minimize the volume of stored PII.; Enable multi-factor authentication for all administrative access to e-commerce platforms.; Educate customers on identifying phishing attempts following a PII leak.
Source: Nine.com.au

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Latest Developments

Update — 2026-08-20 02:02 UTC

Unauthorized system access resulting in a large-scale customer data leak. Exposure of PII for up to 2 million customers, facilitating potential identity theft and phishing campaigns. The breach involved unauthorized access to the retailer’s e-commerce systems, resulting in the theft of customer names, contact details, and purchase histories. While financial data remained secure, the volume of leaked PII significantly increases the risk of targeted phishing and social engineering attacks. The incident is linked to the ‘xpl0itrs’ group, which specializes in leaking corporate data on the dark web.

Corroborating source: news.com.au

Update — 2026-08-20 11:40 UTC

Unauthorized access to an online purchase and order platform. Exposure of customer PII including contact details and purchase histories. An unauthorized third party gained brief access to the company’s online order platform. While financial data remained secure, the theft of names, phone numbers, and email addresses creates a significant risk for targeted phishing and social engineering. The company is currently reviewing its data retention policies to mitigate future risks.

Corroborating source: thecyberexpress.com

Update — 2026-08-25 17:07 UTC

Unauthorized access to customer data via a third-party service provider. Exposure of customer names, emails, phone numbers, and purchase histories. The breach originated from a compromise of an external service provider rather than the company’s internal network. Attackers accessed a subset of customer order histories and PII, though sensitive financial data remained secure. This incident highlights the ongoing risk of supply chain vulnerabilities in the retail sector.

Corroborating source: retailnews.asia

Leave a Reply

Your email address will not be published. Required fields are marked *