Locally Data Breach (2022): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The Locally Data Breach (2022) (reported October 1, 2022) exposed Email addresses, Partial credit card data, Passwords and Phone numbers belonging to roughly 363K people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
In October 2022, Locally, described as an online-to-offline shopping solution, experienced a data breach that exposed information tied to roughly 363,000 people. Public reporting places the incident around 1 October 2022. The company is said to have acknowledged the breach privately; whether affected customers were later notified remains unknown from available detail.
Records associated with the incident describe exposure of names, email and physical addresses, phone numbers, purchase information, partial credit card data (card type and last four digits), and bcrypt password hashes. For people who shopped through or registered with Locally, that combination raises practical questions about account security, contact privacy, and residual fraud risk even when full card numbers were not listed among the exposed fields.
Inside the incident
According to the reported summary, Locally suffered a data breach in October 2022 affecting more than 362,000 individuals, with the broader figure given as 363,000 people affected. The exposed material is described as including names, phone numbers, email addresses, physical addresses, purchase records, credit card type and last four digits, and bcrypt password hashes. Locally acknowledged the breach privately; public detail does not establish whether impacted customers received formal notification afterward.
Timing beyond the October 2022 reporting window, the technical method of intrusion, and any fuller inventory of systems or files involved are not disclosed in the available facts. No threat actor is attributed in the record. Scale is stated in terms of people affected rather than a public breakdown of every data field per person, so the precise completeness of each record cannot be confirmed from what has been reported.
How a breach like this happens
Incidents that expose customer account and transaction-related data often follow familiar patterns, though none of these should be read as a confirmed cause in Locally’s case. Attackers may obtain access through stolen or guessed credentials, unpatched software, misconfigured cloud storage or databases, compromised third-party services, or malware on systems that handle customer information. Once inside, they commonly copy databases or exports that already contain emails, hashed passwords, addresses, and order history because those systems are built to support login, fulfillment, and support.
Password data is frequently stored as cryptographic hashes rather than plain text. Bcrypt is a deliberately slow hashing method designed to make bulk guessing harder; exposure of bcrypt hashes is still serious because offline cracking remains possible if passwords were weak or reused, but it is not the same as immediate disclosure of the original password string. Partial payment data—such as card brand and last four digits—does not by itself equal a full card number, yet it can help fraudsters social-engineer victims or match records from other leaks. How any specific breach unfolded is a matter for forensic investigation; without a published technical account, the pathway here stays undisclosed.
Locally and its sector
Locally is characterized in reporting as an online-to-offline shopping solution—the kind of platform that connects digital discovery or purchase activity with physical retail. Organizations in this sector typically maintain customer accounts, contact details, store or fulfillment preferences, and order or purchase histories so shoppers can find products, complete transactions, and receive support across channels.
That role means such companies often hold identifiers and behavioral data that are useful both for legitimate commerce and for misuse if copied. A breach at a shopping intermediary or retail technology provider can therefore touch people who never thought of the platform as holding sensitive material, simply because they created an account, saved an address, or completed a purchase. The consequence is not only operational disruption for the business but a lasting privacy and security burden for customers whose details may circulate beyond the original system.
What data was at risk
The facts name the following as exposed: email addresses, partial credit card data, passwords, phone numbers, physical addresses, and purchases. The reported summary further specifies names, credit card type and last four digits, and bcrypt password hashes, alongside phone numbers, email and physical addresses, and purchase information, for over 362,000 people in the described set.
Exact per-person completeness is not independently itemized beyond that description. Organizations of this type commonly also retain account metadata, support tickets, or marketing preferences; whether any of those appeared in this incident is unconfirmed. Readers should treat only the named categories as reported and regard anything else as unknown.
Why it matters
Email addresses and phone numbers enable phishing, smishing, and targeted scams that reference real purchases or account details to appear legitimate. Physical addresses increase risks of physical mail fraud or correlation with other public records. Purchase history can reveal habits, household patterns, or higher-value interests that make social engineering more convincing.
Bcrypt password hashes, if cracked, can lead to account takeover on Locally and on any other site where the same password was reused. Partial credit card data alone is limited, but combined with name, address, and phone it can support impersonation when contacting banks or merchants. For the organization, a breach of this scale implies regulatory, contractual, and trust costs, and the uncertainty around customer notification—if it was not clearly carried through—can leave people unaware they should change passwords or watch for fraud. None of this requires assuming negligence; it follows from the types of data reported as exposed and the number of people involved.
If your data was in this breach
If you used Locally around or before the reported period, treat the named data types as potentially exposed. Change your Locally password and any other accounts where you reused that password; prefer a unique password and a password manager. Enable multi-factor authentication wherever it is offered. Watch email and phone for phishing that cites orders, addresses, or partial card details. Review bank and card statements for unfamiliar charges and consider alerts from your card issuer. You may also wish to place fraud alerts with credit reporting services if you are concerned about identity misuse involving your name and address.
Public breach detail can be incomplete, and private acknowledgment does not always equal clear individual notice. As a practical check, readers can run a free exposure scan of their email to see whether their information has surfaced in known breach data, then prioritize password changes and monitoring for any confirmed hits.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
GunAuction.com Data Breach (2022)BreachForums Data Breach (2022)Movie Forums Data Breach (2022)Abandonia (2022) Data Breach (2022)Latest breaches
Read GalaxyWarden’s full analysis of the Locally Data Breach (2022) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.