Back to Blog
medium severity August 19, 2026 · 4 min read Unverified claim — what this is

Oz Hair and Beauty confirms cyber incident — what it means for customers

If you have an account with Oz Hair and Beauty, here’s what is being claimed, and what it would mean for you.

Oz Hair and Beauty has confirmed that an unauthorised party briefly accessed its online order platform, and that it is investigating an online claim about data. The company has not said how many people are involved or which details were taken. A published file reviewed independently contained about 2 million email addresses plus names, phone numbers, suburb-level locations and purchases.

— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Oz Hair and Beauty confirms cyber incident — what it means for customers

Around 18 August 2026, Oz Hair and Beauty confirmed a cyber incident on its own website and through a company spokesperson. It said it had identified that its online purchase and order platform was briefly accessed by an unauthorised third party. After becoming aware of an online claim about data relating to the company, it started an investigation. That investigation, it said, indicates the claim relates to data held by a third-party provider. It has notified New Zealand's Privacy Commissioner. It has not given any number of affected records and has not confirmed that specific personal details were taken from customer accounts.

Already exposed?
You can’t unleak a breach. You can take away what it’s worth.
The free scan shows you every leak tied to your email, and which look-up sites are publishing your name, address and family alongside it. We write to 582 companies.
Check if you are in this breach — free scan →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

On 19 August 2026, Have I Been Pwned described a published dataset linked to this incident. That review found about 2 million unique email addresses, along with names, phone numbers, suburb and postcode, and purchases. Those figures come from the leaked material itself, not from the company. Mainstream Australian news outlets have not reported the story.

Why “it was a third party” does not settle this for you

The official wording is cautious, and it is easy to hear it as reassurance. Access was “brief.” The claim, the company says, appears to involve a vendor. An investigation is still running. All of that can be true and still leave a shopper in the same practical position.

What most coverage will not spell out is this: a large file is already circulating that looks like a customer list. It pairs a name with an email address, a phone number, a suburb and postcode, and a record of purchases. The company has not confirmed that file is theirs. It has also not denied that an incident happened, or that a claim was posted. Attackers do not wait for the final legal wording about whose server was involved. If that combination is sitting next to a well-known shop's name, someone can contact you and already know enough to sound legitimate.

They do not need your password or your full street address to do that. A caller or an email that already knows your name, roughly where you live, and that you buy from Oz Hair and Beauty has a ready-made script: a problem with an order, a refund, a delivery, or “we are contacting you about the breach.” That is the part the vendor-and-investigation framing leaves sitting with you.

There is another gap. The company told a New Zealand privacy regulator. Australian television and major newspapers have not covered this. If you only hear it in a group chat, that silence does not mean it is fake. It also does not mean a clear letter is coming. The honest read is not that this incident emptied anyone's bank account. Passwords, full home addresses, gift-card numbers and payment-card details have not been confirmed. The honest read is that if you have ever ordered there, you should expect more convincing scam contact, and you should not wait for a definitive yes or no about whether your details were in the file.

What to actually expect

  • Emails, texts or phone calls that use your name and mention an Oz Hair and Beauty order, a refund, a delivery problem, or this incident. Treat those as scams unless you contacted the company first through a channel you already trust.
  • Little or no explanation on major Australian news sites, so you may only hear fragments, some of them overstated.
  • A possible further update from the company. It has said it will keep customers updated with accurate information; it has not said it will write to every customer.
  • The published file remaining available. Copies of a leak are not pulled back once they are out.

What you can and cannot fix

If your name, email address, phone number, suburb or postcode, and purchase history were in that published set, that combination cannot be undone. It cannot be recalled from the internet, and nobody can reliably delete it for you.

What still helps, in this order:

  • Treat unexpected contact about an order, a refund, or “your data” as fake. Open the official Oz Hair and Beauty website yourself if you need to check anything. Do not use links, attachments, or phone numbers that arrived in the message.
  • Treat knowledge of your name, your suburb and the fact that you shop there as bait, not as proof the caller is genuine. That is likely the most useful thing a scammer would have from this incident.
  • Cut back what people-search and data-broker sites publish about you — extra phone numbers, relatives, employers, previous addresses. A bare shop record becomes much more dangerous when it can be joined to those listings. Unlike the leaked file, those listings can often actually be removed.
  • If the company later asks customers, on its own website, to change a password or watch a specific account, do that from there. Do not follow that instruction from an email or text you were not expecting.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
Oz Hair and Beauty is one breach. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity Medium
Disclosed August 19, 2026
Affected Unconfirmed
Data exposed NamesEmail addressesPhone numbersSuburb and postcodePurchases
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email