T2 Data Breach (2024): What Was Exposed & What To Do
T2 Data Breach (2024) appeared in a public breach index on April 17, 2024, exposing the names, dates of birth, email addresses, phone numbers, and passwords of 95,000 individuals. If you hold an account with T2, review the index entry and change any exposed password immediately.
In April 2024, roughly 95,000 customer records tied to the T2 tea store appeared on a popular hacking forum. For people who shopped there, that listing raises immediate practical questions: whether their name, contact details, purchase history, or password hash is now circulating, and what steps they should take next. Public reporting does not describe how the data left T2’s systems, only that the records were posted and that they contained a wide range of personal and account information.
The incident matters because the exposed fields go beyond a simple email list. Dates of birth, physical addresses, phone numbers, and purchase records can be combined for fraud or social engineering, while password hashes—even when stored with a modern algorithm—still warrant password changes if the same credentials are reused elsewhere.
Breaking down the breach
According to the available record, the breach was reported on 17 April 2024. Approximately 95,000 records from the T2 tea store were posted to a popular hacking forum. The posted data included email addresses, physical addresses, names, phone numbers, dates of birth, purchase details, salutations, and passwords stored as scrypt hashes. No further public detail has been provided on the exact date the data was taken, the technical method used, or whether the company confirmed the full scope of the incident. The forum posting itself is the primary public claim that the records originated from T2.
How a breach like this happens
Incidents that end with customer databases appearing on hacking forums typically follow a familiar pattern, though the precise path in any single case is often undisclosed. Attackers may obtain access through stolen credentials, unpatched software, misconfigured cloud storage, or compromised third-party services that hold customer data. Once inside, they extract database tables or export files containing personal and account fields. The material is then packaged and offered or simply dumped on forums where other actors can download it. Password fields that appear as scrypt hashes indicate the organisation used a deliberately slow hashing function designed to resist brute-force attacks; that does not eliminate risk if the same password was reused on other sites, but it does make offline cracking more expensive. No specific threat group has been attributed to this incident, and public sources do not name one.
T2 and its sector
T2 operates as a specialty tea retailer, selling loose-leaf teas, accessories, and related products through physical stores and online channels. Retailers of this kind routinely collect the information needed to process orders, manage loyalty or mailing lists, and fulfil deliveries: names, email and postal addresses, phone numbers, dates of birth for age-restricted or promotional purposes, purchase histories, and account credentials. A breach at a consumer-facing tea brand is consequential because the customer base is ordinary shoppers rather than a narrow professional group; the same people may reuse passwords across shopping, banking, and email accounts. Exposure of purchase records can also reveal lifestyle details that make phishing messages more convincing.
What data was at risk
The forum posting and subsequent reporting named the following categories as present in the 95,000 records:
- Dates of birth
- Email addresses
- Names
- Passwords (stored as scrypt hashes)
- Phone numbers
- Physical addresses
- Purchases
- Salutations
Exact contents of every record are not independently verified beyond the public claim, and no additional fields have been confirmed. Organisations of this type typically hold payment-token or order-fulfilment data as well, but those elements are not listed among the exposed types in the available facts.
What's at stake
For affected individuals the concrete risks are identity-related fraud, targeted phishing, and credential stuffing. A date of birth combined with a full name and address can support attempts to open accounts or reset passwords elsewhere. Phone numbers and email addresses enable smishing or spoofed customer-service messages that reference real purchases. Even scrypt-hashed passwords become a concern if the same password is used on other services; attackers can attempt offline cracking or simply try the plaintext if it is weak. For the organisation, the stakes include customer distrust, potential regulatory scrutiny under privacy laws, and the operational cost of notification and remediation. Public detail does not quantify financial loss or confirm whether payment-card data was involved.
Were you affected?
If you have ever created an account or placed an order with T2, treat the possibility of exposure seriously. Change any password you used on the T2 site, and change it on every other service where you reused the same or a similar password. Enable multi-factor authentication wherever it is offered. Monitor bank and card statements for unexpected activity and be sceptical of unsolicited messages that reference tea purchases or ask you to “verify” account details. You can also run a free exposure scan of your email address to check whether it has appeared in known breach data sets; that check will not prove or disprove involvement in this specific incident, but it can surface other places your information has already circulated. Keep records of any suspicious contact and report confirmed fraud to the relevant authorities and your financial institutions.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
More recent breaches
BitView Data Breach (2024)Yonéma Data Breach (2024)1win Data Breach (2024)SuperDraft Data Breach (2024)Latest breaches
Read GalaxyWarden’s full analysis of the T2 Data Breach (2024) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.