Oz Hair and Beauty confirms cyber incident — what it means for customers
If you have an account with Oz Hair and Beauty, here’s what is being claimed, and what it would mean for you.
Oz Hair and Beauty has confirmed that an unauthorised party briefly accessed its online order platform, and that it is investigating an online claim about data. The company has not said how many people are involved or which details were taken. A published file reviewed independently contained about 2 million email addresses plus names, phone numbers, suburb-level locations and purchases.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Oz Hair and Beauty customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
Around 18 August 2026, Oz Hair and Beauty confirmed a cyber incident on its own website and through a company spokesperson. It said it had identified that its online purchase and order platform was briefly accessed by an unauthorised third party. After becoming aware of an online claim about data relating to the company, it started an investigation. That investigation, it said, indicates the claim relates to data held by a third-party provider. It has notified New Zealand's Privacy Commissioner. It has not given any number of affected records and has not confirmed that specific personal details were taken from customer accounts.
On 19 August 2026, Have I Been Pwned described a published dataset linked to this incident. That review found about 2 million unique email addresses, along with names, phone numbers, suburb and postcode, and purchases. Those figures come from the leaked material itself, not from the company. Mainstream Australian news outlets have not reported the story.
Why “it was a third party” does not settle this for you
The official wording is cautious, and it is easy to hear it as reassurance. Access was “brief.” The claim, the company says, appears to involve a vendor. An investigation is still running. All of that can be true and still leave a shopper in the same practical position.
What most coverage will not spell out is this: a large file is already circulating that looks like a customer list. It pairs a name with an email address, a phone number, a suburb and postcode, and a record of purchases. The company has not confirmed that file is theirs. It has also not denied that an incident happened, or that a claim was posted. Attackers do not wait for the final legal wording about whose server was involved. If that combination is sitting next to a well-known shop's name, someone can contact you and already know enough to sound legitimate.
Advertisement
BATECH StudioWe build it.We run it.Web apps, AI pipelines and internal tools — under your brand, not ours.Tell us what you need →
BATECH Studio and GalaxyWarden share common ownership.
They do not need your password or your full street address to do that. A caller or an email that already knows your name, roughly where you live, and that you buy from Oz Hair and Beauty has a ready-made script: a problem with an order, a refund, a delivery, or “we are contacting you about the breach.” That is the part the vendor-and-investigation framing leaves sitting with you.
There is another gap. The company told a New Zealand privacy regulator. Australian television and major newspapers have not covered this. If you only hear it in a group chat, that silence does not mean it is fake. It also does not mean a clear letter is coming. The honest read is not that this incident emptied anyone's bank account. Passwords, full home addresses, gift-card numbers and payment-card details have not been confirmed. The honest read is that if you have ever ordered there, you should expect more convincing scam contact, and you should not wait for a definitive yes or no about whether your details were in the file.
What to actually expect
- Emails, texts or phone calls that use your name and mention an Oz Hair and Beauty order, a refund, a delivery problem, or this incident. Treat those as scams unless you contacted the company first through a channel you already trust.
- Little or no explanation on major Australian news sites, so you may only hear fragments, some of them overstated.
- A possible further update from the company. It has said it will keep customers updated with accurate information; it has not said it will write to every customer.
- The published file remaining available. Copies of a leak are not pulled back once they are out.
What you can and cannot fix
If your name, email address, phone number, suburb or postcode, and purchase history were in that published set, that combination cannot be undone. It cannot be recalled from the internet, and nobody can reliably delete it for you.
What still helps, in this order:
- Treat unexpected contact about an order, a refund, or “your data” as fake. Open the official Oz Hair and Beauty website yourself if you need to check anything. Do not use links, attachments, or phone numbers that arrived in the message.
- Treat knowledge of your name, your suburb and the fact that you shop there as bait, not as proof the caller is genuine. That is likely the most useful thing a scammer would have from this incident.
- Cut back what people-search and data-broker sites publish about you — extra phone numbers, relatives, employers, previous addresses. A bare shop record becomes much more dangerous when it can be joined to those listings. Unlike the leaked file, those listings can often actually be removed.
- If the company later asks customers, on its own website, to change a password or watch a specific account, do that from there. Do not follow that instruction from an email or text you were not expecting.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
Report details & sourcing
Related breaches
Pokémon Center data breach: what UK and Germany customers should know
A cyberattack on CEVA Logistics, the firm that ships Pokémon Center orders to the UK and Germany, ma…
Did SafePal leak my home address? What the 2026 breach actually means
SafePal confirmed that a flaw in its order-tracking tool exposed the names, emails, shipping address…
Pokémon Center data breach: what UK and Germany customers need to know
Pokémon Center has emailed some customers that CEVA Logistics, which ships its UK and Germany orders…