LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Oz Hair and Beauty data breach: what was taken and what you should do

CRITICAL severityReportedHow we verify

Oz Hair and Beauty data breach: what was taken and what you should do: What Was Reportedly Exposed & What To Do

RBRecent Breaches Breach Intelligence·August 22, 2026
Oz Hair and Beauty data breach: what was taken and what you should do

Reported August 22, 2026.

CRITICAL
Severity
5
Data types exposed
August 22, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Oz Hair and Beauty data breach: what was taken and what you should do (reported August 22, 2026) exposed Full names, Email addresses, Phone numbers and Purchase data. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
CRITICAL severityReported
Exposes financial data.
Based on public reporting. Not independently confirmed by the named organization.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Oz Hair and Beauty has confirmed that an unauthorised party accessed some customer details from its online shop. According to the company’s disclosure, the incident involved names, email addresses and/or mobile numbers, and basic purchase information. Payment cards and passwords were not involved. The number of people affected remains unknown. The company is emailing those it believes are affected and has stated that the website remains safe to use. The matter was reported on 22 August 2026.

For customers who shopped online with the retailer, the confirmed exposure of contact and purchase-related details raises practical questions about unwanted contact, phishing risk and the long-term handling of that information. Public detail beyond the company’s statement is limited.

Breaking down the breach

Oz Hair and Beauty has stated that an unauthorised party obtained access to some customer details held in connection with its online shop. The company has identified the categories of information involved as names, emails and/or mobile numbers, and basic purchase information, including purchase data and purchase locations. It has explicitly indicated that payment card details and passwords were not part of what was accessed.

The scale of the incident—how many customer records were involved—has not been disclosed and is recorded as unknown. The precise method of access, the duration of any unauthorised presence, and the exact date range of the activity have not been made public in the available disclosure. The company has said it is contacting affected customers by email and that its website continues to be safe for use. No further technical findings or independent verification details have been released in the material provided.

How a breach like this happens

Incidents in which customer records from an online retail system become accessible to an unauthorised party commonly arise from weaknesses that allow someone outside the organisation to reach databases, administrative interfaces, or exported files that hold order and account information. Typical pathways, described here only as general background and not as a finding about this case, include compromised staff or supplier credentials, unpatched software on e-commerce platforms, misconfigured cloud storage, or flaws in web applications that process orders and customer profiles.

Once access is obtained, an attacker may copy tables or exports containing names, contact fields and order histories. Because many retail systems separate payment processing from the merchant’s own customer database—often through third-party payment gateways—card numbers and passwords are frequently stored elsewhere or not stored at all, which aligns with organisations sometimes being able to state that those items were not exposed. Without a specific attribution in this case, no threat group or technique should be assumed; the general pattern is simply unauthorised access followed by exfiltration of whatever customer fields the system held.

Oz Hair and Beauty data breach: what was taken and what you should do and its sector

Oz Hair and Beauty operates as a retailer in the hair and beauty products sector, selling goods to consumers through physical and online channels. Businesses of this type typically maintain customer accounts or guest-checkout records that include identity and contact fields, order histories, delivery or collection details, and marketing preferences so they can fulfil purchases and communicate with buyers.

A breach affecting an online shop in this sector is consequential because the data set is directly tied to real purchasing behaviour and reachable contact points. Even when payment credentials are not involved, names combined with email addresses, phone numbers and purchase context can be reused for targeted phishing, smishing or social-engineering attempts that reference a plausible recent order. The company’s confirmation that it is notifying affected customers and that the site remains usable is the primary public guidance available so far.

The information in question

The disclosure names the following categories as involved: full names, email addresses, phone numbers, purchase data and purchase locations. The company has stated that payment cards and passwords were not involved. The exact volume of records, whether every field was present for every affected person, and any additional attributes beyond those listed have not been detailed publicly.

Organisations in online retail commonly hold similar fields in order-management and customer-relationship systems. In this incident, only the categories confirmed by Oz Hair and Beauty should be treated as known; anything further remains unconfirmed.

Why it matters

For individuals, the practical risks centre on misuse of contact details and purchase context. An email address or mobile number paired with a name and knowledge of a past order can make fraudulent messages appear more credible, increasing the chance that someone clicks a malicious link or reveals further information. Purchase locations and order patterns can also support more tailored scams. Because passwords and payment cards are stated not to have been involved, the immediate risk of account takeover on the retailer’s site or direct card fraud from this incident is lower than in breaches that include those elements; residual risk still exists if customers reuse passwords elsewhere or if stolen contact data is combined with information from other sources.

For the organisation, the incident creates obligations to notify affected people, manage customer trust, and review how customer data is segmented and protected in the online shop environment. The absence of a published figure for people affected means the full operational and reputational scope is not yet clear from public information alone.

If your data was in this breach

If you have received an email from Oz Hair and Beauty about this incident, or if you have shopped on its online store and are concerned, treat unsolicited messages that claim to relate to the breach with caution. Verify any link or request by navigating to the company’s site independently rather than clicking through from an email or text. Monitor your email and phone for phishing or smishing that references hair, beauty or recent orders. Because passwords were not involved according to the company, a password change on the Oz Hair and Beauty site is not specifically indicated by the disclosure; still use unique passwords and multi-factor authentication where you can on important accounts. Payment cards were also stated not to be involved, but reviewing bank and card statements for unfamiliar charges remains sensible general practice.

You can run a free exposure scan of your email address to check whether your information has surfaced in known breach data sets. Keep any notification from the company for your records, and follow only official channels if further advice is issued. Public detail on this incident remains limited to the company’s confirmation of unauthorised access to the named customer fields from its online shop.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

More recent breaches

Oz Hair and Beauty confirms cyber incident — what it means for customersAugust 19, 2026Pokémon Center data breach: was my name, address and order exposed?August 18, 2026Pokémon Center data breach: what UK and German shoppers should knowAugust 18, 2026Simian Drukland data breach: what we know and what customers should doAugust 17, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Oz Hair and Beauty data breach: what was taken and what you should do →

Based on public reporting

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram