LuLu Data Breach (2024)
If you are a customer of LuLu, here’s what’s now in circulation.
In July 2024, the Emirati-based LuLu retail store suffered a data breach. The impacted data included 190k email addresses and associated phone numbers which were subsequently shared on a popular hacking forum. The following month, the threat of leaking the full database was carried out and a backup from October 2022 with a further 2.6M unique email addresses appeared. This data also included names, physical addresses, orders and PBKDF2 password hashes.
LuLu customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
On July 6, 2024, LuLu, the large Emirati-based retail chain, was listed in a breach notification on Have I Been Pwned after attackers published nearly three million customer records. The breach ultimately exposed the personal details of 2.8 million people, including you or members of your family if you have ever shopped at LuLu stores or used their online services.
Reported Details from the Breach
The primary disclosure on Have I Been Pwned states that a backup dated October 2022 was exfiltrated and later published. It contained 2.8 million unique email addresses along with names, phone numbers, physical addresses, purchase history, and PBKDF2 password hashes. An earlier sample of roughly 190,000 email addresses and phone numbers had already circulated on a popular hacking forum in July 2024 before the full database appeared the following month. The notification does not specify the initial attack vector or the exact ransomware group responsible.
Advertisement
BATECH StudioWe build it.We run it.Web apps, AI pipelines and internal tools — under your brand, not ours.Tell us what you need →
BATECH Studio and GalaxyWarden share common ownership.
Why This Matters for You and Your Family
When a retailer the size of LuLu loses a backup containing names, physical addresses, phone numbers, and password hashes, the information becomes raw material for identity theft, phishing campaigns, and account takeovers. If you have shopped there, your home address and phone number are now available to anyone willing to search dark-web marketplaces. Password hashes, even when salted with PBKDF2, can still be cracked offline given enough time and computing power, especially if you reused the same password elsewhere. Children or other household members who share an email address or phone number for family orders are also placed at risk.
Doxxing and Identity-Chain Risks
The combination of email addresses, phone numbers, and physical addresses allows attackers to link your shopping account to other online profiles. A single leaked credential can cascade into gaming accounts, social media, or financial services that use the same email. Public records and people-search sites then fill in the gaps, creating a complete identity chain that can lead to doxxing, swatting, or targeted scams. Credential leaks of this nature frequently surface in subsequent breaches, extending the exposure window for months or years.
What to Do
- Run a DoxxScan to map every link between your handles, emails, phone numbers, and real identity, with cleanup handled by the service.
- Rotate the password you used at LuLu anywhere it is reused and immediately enable 2FA through an authenticator app rather than SMS.
- Enable continuous DoxxScan monitoring across 13.1B+ breach records and 100+ platforms so the next exposure is caught in hours, not months.
- Cover the household with DoxxScan family coverage that extends to dependents and children’s gaming accounts that often chain back to the same address or parent email.
- Let remediation specialists handle takedown requests across data brokers and leak sites on your behalf.
The incident underscores how retail breaches continue to feed the underground economy long after the initial headlines fade. One practical step forward is to treat every exposed password hash as a potential master key to your digital life and act before criminals do. DoxxScan by GalaxyWarden delivers continuous monitoring across 13.1 billion+ breach records and more than 100 platforms, AI-powered identity-chain mapping, hands-on remediation by specialists, and full household coverage that includes children’s gaming accounts vulnerable to the same credential-stuffing chains seen in breaches like LuLu.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: a staff address in a leak does not mean you were breached — it usually means a third party was. We monitor a domain against 13.1B+ leaked records and tell you when one of your people appears. See what we would check →
Report details & sourcing
Related breaches
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…
149 Million Credential Mega-Exposure — January 2026
Security researchers discovered a publicly exposed 96 GB database with 149 million unique logins cov…
Under Armour 72M Customer Email Dataset Resurfaces — January 2026
72 million user emails from a prior Under Armour breach were reposted publicly in January 2026, ampl…