LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Lazada RedMart Data Breach (2020)

CRITICAL severityConfirmedHow we verify

Lazada RedMart Data Breach (2020): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 30, 2020

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Lazada RedMart Data Breach (2020)

Reported July 30, 2020. Approximately 1.1M people affected.

CRITICAL
Severity
1.1M
People affected
6
Data types exposed
July 30, 2020
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Lazada RedMart Data Breach (2020) (reported July 30, 2020) exposed Email addresses, Names, Partial credit card data and Passwords belonging to roughly 1.1M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
CRITICAL severityConfirmed
Exposes financial data.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Lazada RedMart Data Breach (2020) breach?
1.1M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

What is known is that a dataset associated with Lazada RedMart, containing records for 1.1 million customers, appeared for sale on an online marketplace in October 2020. The records included information current as of July 2020. Public reporting on the incident began around July 30, 2020, and the material was described as customer data from the company’s operations. The practical stakes for the people whose information may be involved are straightforward. Email addresses, names, phone numbers and physical addresses can be used for targeted phishing or unwanted contact. Partial credit card details combined with other identifiers can aid attempts at account takeover or fraud. Passwords stored as SHA-1 hashes, if cracked, could allow access to other accounts where the same credentials were reused.

What happened

News of the incident surfaced in October 2020 when the dataset was offered for sale on an online marketplace. The material was reported to contain 1.1 million records with customer email addresses, names, phone numbers, physical addresses, partial credit card numbers and passwords stored as SHA-1 hashes. The records extended to activity as recent as July 2020. No official statement from the company detailing the method or exact timing of the incident has been referenced in the available reporting.

How a breach like this happens

Incidents involving the exposure of customer databases from online retailers commonly begin with unauthorised access to internal systems. Attackers may exploit vulnerabilities in web applications, compromised credentials of staff or third-party vendors, or misconfigured storage that leaves data accessible. Once obtained, the data is often packaged and offered for sale on forums or marketplaces rather than used directly by the initial intruder. The presence of hashed passwords indicates the material was taken from a customer database rather than intercepted in transit.

Lazada RedMart and its sector

Lazada RedMart operates as an online grocery and retail platform serving customers in several Southeast Asian markets. Companies in this sector routinely collect and store names, contact details, delivery addresses and payment information to process orders and manage accounts. Because these platforms handle recurring transactions and maintain long-term customer profiles, the datasets they hold can remain valuable for extended periods after any initial compromise.

What was likely exposed

The reported dataset explicitly included email addresses, names, phone numbers, physical addresses, partial credit card numbers and passwords stored as SHA-1 hashes. Exact confirmation of every field present in the full 1.1 million records has not been independently verified beyond the marketplace listing. Organisations of this type typically also retain order histories and account creation dates, but those elements were not named in the available description of the exposed material.

Why it matters

For individuals, the combination of contact details with partial payment information raises the possibility of increased phishing attempts or attempts to exploit reused passwords on other sites. Partial credit card data alone is usually insufficient for direct fraud, yet when paired with names and addresses it can support more convincing social-engineering attacks. For the organisation, the incident adds to the record of retail-sector exposures and may prompt regulatory scrutiny or requirements to improve data-handling practices.

What to do if you're exposed

Anyone who used Lazada RedMart around or before July 2020 should treat their account password as potentially compromised and change it, along with any other accounts that share the same password. Enable multi-factor authentication where available and monitor bank or card statements for unusual activity. Readers can run a free exposure scan of their email address against known breach data to check whether their information appears in this or other documented incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyLazada RedMart security record
73/100
DoxxScan™ · Moderate doxx risk
C- 64Below-average record

1 reported incident on record.

See Lazada RedMart’s full breach history →

More recent breaches

MEO Data Breach (2020)December 24, 2020NetGalley Data Breach (2020)December 21, 2020MMG Fusion Data Breach (2020)December 20, 2020DriveSure Data Breach (2020)December 19, 2020

Latest breaches

Read GalaxyWarden’s full analysis of the Lazada RedMart Data Breach (2020) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram