On March 27, 2024, the personal information of up to 5 million Lookiero customers appeared in a data set posted to a popular hacking forum. The online personal styling service, which ships curated clothing selections to subscribers, had its customer records exposed in a breach that occurred earlier that year. Anyone who provided contact details to Lookiero may now find their email addresses, names, phone numbers, and physical addresses circulating among criminals.
Named in this incident?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Lookiero
Get alerted the next time Lookiero files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Lookiero’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Disclosure
The listing on Have I Been Pwned states that the Lookiero breach dates to March 2024 and contains approximately 5 million unique email addresses. Many of the records also include full names, phone numbers, and home addresses. The company was contacted directly about the incident and responded that it would “look into it and get back to you if necessary,” without confirming the breach or notifying affected customers at that time. The disclosure does not specify the initial attack vector, whether data was encrypted, or if a ransom demand was made.
Why This Matters for You and Your Family
When your name, email, phone number, and home address are bundled together, the information becomes far more valuable to identity thieves than any single piece alone. Criminals can use it to impersonate you with banks, retailers, or government agencies, or to craft convincing phishing messages that reference your recent clothing shipment or styling preferences. For families, the exposure often reaches spouses or dependents listed on joint accounts, increasing the chance that one compromised record leads to broader household targeting. The medium severity rating reflects the scale—5 million records—and the fact that physical addresses allow criminals to link digital identities to real-world locations.
Doxxing and Identity-Chain Risks
Once an address and phone number are public, attackers can cross-reference them against people-search sites, social-media profiles, and other leaks to build a complete picture of your life. This identity chain frequently extends to family members, revealing children’s names, schools, or even gaming usernames. Credential leaks of this type often cascade into account takeovers on shopping sites, email, or streaming services that share the same password. The result is doxxing that can escalate from nuisance spam to targeted harassment or financial fraud. Physical addresses are especially dangerous because they enable swatting attempts, mail theft, or in-person scams.