Shoe Zone Data Breach (2024): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The Shoe Zone Data Breach (2024) (reported June 28, 2024) exposed Email addresses, Names, Partial credit card data and Physical addresses belonging to roughly 46K people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
In June 2024 the UK footwear retailer Shoe Zone disclosed a data breach involving customer order information. Public reporting dated 28 June 2024 states that material from the incident was later offered for sale on a popular hacking forum. The disclosed material covered more than 100,000 orders and approximately 46,000 unique email addresses, together with associated names, physical addresses, purchase details and partial credit-card data.
The episode matters because it places real customer records into circulation outside the company’s control. Exact technical details of how the data left Shoe Zone’s systems remain limited in public accounts, yet the volume and nature of the records already create concrete risks for the people whose information appears in them.
Inside the incident
According to the available public summary, Shoe Zone confirmed a data breach in June 2024. Shortly afterwards the same data set was listed for sale on a well-known hacking forum. The listing claimed to contain records of over 100,000 orders. Those records included customer names, physical addresses, purchase histories, partial credit-card numbers (card type and last four digits) and 46,000 unique email addresses. No further official figures for the total number of individuals affected beyond the 46,000 email addresses have been released. The method of intrusion, the precise date range of the compromise, and any internal detection timeline have not been disclosed in the public record.
How a breach like this happens
Retail organisations that process online and in-store orders typically store customer data in databases connected to e-commerce platforms, payment gateways and loyalty systems. Attackers commonly gain initial access through stolen credentials, unpatched software vulnerabilities, or phishing that targets staff with administrative rights. Once inside, they may extract large volumes of order and customer records before the intrusion is noticed. In many cases the stolen data is later advertised on criminal forums as a way to monetise the theft. No specific threat group has been publicly attributed to the Shoe Zone incident, so the precise pathway used here remains unconfirmed.
Shoe Zone and its sector
Shoe Zone is a high-street and online footwear retailer operating across the United Kingdom. Like other chains in the sector it maintains customer accounts, processes card payments, records delivery addresses and stores order histories so that purchases can be fulfilled and returns handled. Retailers of this type routinely hold contact details, partial payment-card information and transaction logs. A breach of those systems is consequential because the data can be reused for fraud, phishing or identity-related crime long after the original incident. The sector as a whole has seen repeated targeting of customer databases precisely because the combination of personal and transactional information is valuable to criminals.
The information in question
Public reporting names the following categories of data as exposed: email addresses, names, physical addresses, purchase records and partial credit-card data (card type and last four digits). The data set is described as covering more than 100,000 orders and 46,000 unique email addresses. No additional data types have been confirmed. Organisations of this kind commonly also retain phone numbers, full payment-card details or loyalty-account information, but those elements are not listed in the disclosed material and therefore remain unconfirmed for this incident.
What's at stake
For individuals whose records appear in the set, the immediate risks include targeted phishing emails that reference genuine past purchases, attempts to social-engineer further personal details, and the possible use of partial card data in combination with other leaked information to attempt fraudulent transactions. Physical addresses can be used for more sophisticated scams or physical mail fraud. For Shoe Zone the consequences include regulatory scrutiny under UK data-protection rules, potential notification costs, and longer-term damage to customer trust. Because the data has already been offered for sale, the exposure is not theoretical; the records are circulating outside the company’s control.
Were you affected?
Anyone who has shopped with Shoe Zone, particularly online, should treat the possibility of inclusion seriously. Practical first steps include:
- Monitor bank and card statements for unexpected activity and contact the issuer promptly if anything appears irregular.
- Be sceptical of unsolicited emails or calls that claim to relate to past Shoe Zone orders; verify any request through official channels.
- Consider changing passwords on any accounts that reuse credentials linked to the email address used with Shoe Zone.
- Enable multi-factor authentication wherever available on financial and email accounts.
Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Public detail on the full scope of this incident remains limited, so continued vigilance is the most reliable immediate response.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Speedio Data Breach (2024)Young Living Essential Oils Data Breach (2024)Senior Dating Data Breach (2024)FlipaClip Data Breach (2024)Latest breaches
Read GalaxyWarden’s full analysis of the Shoe Zone Data Breach (2024) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.