LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › LuLu Data Breach (2024)

CRITICAL severityConfirmedHow we verify

LuLu Data Breach (2024): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 6, 2024

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

LuLu Data Breach (2024)

Reported July 6, 2024. Approximately 2.8M people affected.

CRITICAL
Severity
2.8M
People affected
6
Data types exposed
July 6, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The LuLu Data Breach (2024) (reported July 6, 2024) exposed Email addresses, Names, Passwords and Phone numbers belonging to roughly 2.8M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
CRITICAL severityConfirmed
Account credentials exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the LuLu Data Breach (2024) breach?
2.8M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In July 2024, roughly 2.8 million people who had shopped with or registered accounts at the Emirati retail chain LuLu found their personal details circulating beyond the company’s control. For those individuals the practical stakes are immediate: email addresses and phone numbers that can be used for targeted phishing, physical addresses that can enable real-world contact, purchase histories that reveal habits, and password hashes that, if cracked, open other accounts that reuse the same credentials.

Public reporting places the first appearance of a portion of the data on a popular hacking forum that same month, followed weeks later by the release of a larger backup. The incident therefore sits at the intersection of retail customer records and the secondary market for personal data, where the value of the information lies less in any single field than in the combination of identity, contact and transaction details.

Inside the incident

According to the available record, the Emirati-based LuLu retail store experienced a data breach that became publicly visible in July 2024. An initial set of approximately 190,000 email addresses and associated phone numbers was shared on a popular hacking forum. The following month the full database threat was carried out: a backup dated October 2022 containing a further 2.6 million unique email addresses was released. That larger dump also included names, physical addresses, order information and PBKDF2 password hashes. The combined figure of people affected is reported as 2.8 million. No further technical details about the initial intrusion method, the precise systems compromised, or any ransom demand have been disclosed in the public summary.

How a breach like this happens

Retail organisations typically store customer account data, loyalty records and order histories in databases that are reachable by internal applications and, sometimes, by third-party services. Common pathways into such systems include stolen or weak credentials used against remote-access portals, unpatched software vulnerabilities, misconfigured cloud storage, or compromised supplier accounts that already hold legitimate access. Once inside, an attacker can copy large tables of customer records. Password fields are often stored as one-way hashes; PBKDF2 is a deliberately slow hashing function intended to slow brute-force attempts, yet the hashes remain useful to attackers who can attempt offline cracking with modern hardware. After exfiltration, portions of the data are frequently posted on forums either as proof of possession or as a full dump, after which the information can be traded, used for credential stuffing, or combined with other leaked sets.

None of these general mechanisms has been confirmed as the vector in the LuLu case; they simply describe how incidents of this type commonly unfold when customer databases leave organisational control.

LuLu and its sector

LuLu operates as a large retail and hypermarket chain headquartered in the United Arab Emirates, serving customers across the Gulf region and beyond. Retailers of this scale routinely maintain customer accounts for online ordering, loyalty programmes and home delivery; those accounts typically hold names, contact details, delivery addresses and purchase histories. Because the business model depends on repeat customers and convenient fulfilment, the volume of personal data held is substantial. A breach therefore affects not only the organisation’s operational reputation but also the everyday privacy of people who expected their shopping and contact information to remain under the retailer’s control.

What data was at risk

The public summary names the following categories as exposed: email addresses, names, passwords (specifically PBKDF2 hashes), phone numbers, physical addresses and purchases (also described as orders). The initial forum post contained roughly 190,000 email addresses paired with phone numbers; the later October 2022 backup added approximately 2.6 million further unique email addresses together with the remaining fields. Exact file sizes, database schemas or additional data elements beyond those listed have not been disclosed.

What's at stake

For affected individuals the concrete risks include phishing or smishing campaigns that reference real purchase history or delivery addresses, making the messages more convincing. Reused passwords, if recovered from the PBKDF2 hashes, can grant access to email, banking or social-media accounts. Physical addresses raise the possibility of unwanted contact or social-engineering attempts that rely on knowledge of a person’s home or workplace. For LuLu the organisational stakes centre on customer trust, potential regulatory scrutiny under applicable data-protection rules, and the cost of remediation and notification. Because the backup originated in 2022, some of the records may already be outdated, yet even older contact details retain value for fraudsters who specialise in long-term credential reuse.

What to do if you're exposed

If you have ever created an account or placed an order with LuLu, treat the possibility of exposure as real. Change any password that may have been reused elsewhere, and enable multi-factor authentication on important accounts. Monitor bank and credit statements for unfamiliar activity and be sceptical of unsolicited messages that claim to relate to past purchases. Consider placing a fraud alert with credit bureaux if you live in a jurisdiction that offers that service. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets; such a scan provides an early indication of whether further monitoring is warranted.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyLuLu security record
73/100
DoxxScan™ · Moderate doxx risk
C- 64Below-average record

1 reported incident on record.

See LuLu’s full breach history →

More recent breaches

BitView Data Breach (2024)December 14, 2024Yonéma Data Breach (2024)November 21, 20241win Data Breach (2024)November 2, 2024SuperDraft Data Breach (2024)October 27, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the LuLu Data Breach (2024) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram