LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › digiDirect Data Breach (2024)

MEDIUM severityConfirmedHow we verify

digiDirect Data Breach (2024): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·September 29, 2024

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

digiDirect Data Breach (2024)

Reported September 29, 2024. Approximately 304K people affected.

MEDIUM
Severity
304K
People affected
5
Data types exposed
September 29, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

A data breach affecting digiDirect was disclosed on September 29, 2024, exposing personal information of approximately 304,000 individuals, including names, dates of birth, email addresses, phone numbers, and physical addresses. If you have an account with digiDirect, check your email for any official notice and consider monitoring your accounts for unusual activity.

Severity & verification
MEDIUM severityConfirmed
Contact / identity PII exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the digiDirect Data Breach (2024) breach?
304K accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Retail and consumer-facing businesses remain frequent targets in the current cyber-threat landscape, where customer databases continue to surface on underground forums long after initial compromises. Against that backdrop, a data breach involving the Australian retailer digiDirect was reported on 29 September 2024. Public reporting indicates that more than 300,000 rows of customer-related information were published to a popular hacking forum, exposing personal details of roughly 304,000 people. The incident underscores how readily such records can circulate once they leave an organisation’s control, with direct implications for the individuals whose information appears in the dataset.

What is known so far is limited to the published material itself and the accompanying claims; many operational details remain undisclosed. The following account stays strictly within those What's Publicly Reported while placing the event in its broader context for anyone who may have shopped with digiDirect or whose details appear in the exposed records.

Breaking down the breach

In September 2024 a data set attributed to digiDirect was posted on a popular hacking forum. The material comprised over 300,000 rows and is reported to have affected approximately 304,000 people. The fields listed as present include dates of birth, email addresses, names, phone numbers and physical addresses. Roughly half of the email addresses were associated with domains belonging to external marketplaces such as Amazon, eBay and Westfield. No further technical details—such as the precise date of the original intrusion, the method of access, or any ransom demand—have been publicly confirmed. The reporting date of 29 September 2024 marks when the forum publication became known; the actual timeline of the compromise itself is not disclosed.

How a breach like this happens

Incidents of this type typically begin with unauthorised access to a customer or order-management system. Common entry points include compromised credentials, unpatched software vulnerabilities, or misconfigured cloud storage. Once inside, an attacker may extract database tables containing contact and identity fields, then package the data for sale or free distribution on criminal forums. In many cases the organisation learns of the exposure only after the material appears publicly. No specific threat actor has been attributed to the digiDirect incident, and the precise vector used here remains unconfirmed. The pattern, however, is familiar: personal data collected for legitimate retail purposes becomes available for secondary misuse once it leaves the original environment.

digiDirect and its sector

digiDirect is an Australian retailer. Like other businesses in the consumer-electronics and photography retail sector, it routinely collects customer information to process orders, manage accounts, arrange deliveries and provide after-sales support. Such organisations typically hold names, contact details, shipping addresses and dates of birth for warranty or identity-verification purposes. A breach at a retailer of this kind is consequential because the data set often combines multiple identity elements that can be cross-referenced with other leaks, increasing the practical value of the records to fraudsters. The presence of email addresses linked to major marketplaces further suggests that some customers may have used third-party login or checkout services, expanding the potential reach of the exposure beyond digiDirect’s own customer base.

The information in question

The published material is reported to contain dates of birth, email addresses, names, phone numbers and physical addresses. Approximately half the email addresses belonged to domains associated with external marketplaces including Amazon, eBay and Westfield. No other data categories have been confirmed. Organisations of this type commonly store additional fields such as order histories or payment-token references, yet those elements are not listed among the exposed records and therefore remain unconfirmed. The exact contents of every row are known only from the forum publication itself; independent verification of completeness or accuracy has not been publicly detailed.

Why it matters

For affected individuals the combination of name, date of birth, physical address, phone number and email creates a ready-made profile that can be used for targeted phishing, account-takeover attempts or identity-fraud applications. Even partial matches with other leaked data sets can enable more convincing social-engineering attacks. For digiDirect the publication raises operational and reputational considerations: customers may need support, regulators may seek explanations, and the company must assess whether residual access paths remain open. Because the data appeared on a public forum, the records are likely to circulate further among criminal communities, prolonging the window of risk well beyond the initial disclosure date.

Were you affected?

If you have ever created an account or placed an order with digiDirect, treat the possibility of exposure seriously. Begin by changing passwords on any accounts that used the same email address, enable multi-factor authentication where available, and monitor bank and credit statements for unexpected activity. Be alert to unsolicited messages that reference your personal details or claim to come from digiDirect or related marketplaces. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Early awareness remains the most practical first step while further official notifications, if any, are still pending.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanydigiDirect security record
74/100
DoxxScan™ · Moderate doxx risk
B 80Good record

1 reported incident on record.

See digiDirect’s full breach history →

More recent breaches

Speedio Data Breach (2024)December 24, 2024Young Living Essential Oils Data Breach (2024)December 11, 2024Senior Dating Data Breach (2024)November 23, 2024FlipaClip Data Breach (2024)November 18, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the digiDirect Data Breach (2024) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram