Oz Hair and Beauty data breach: what was taken and what to do now
If you are a customer of Oz Hair and Beauty, here’s what is being claimed, and what it would mean for you.
Oz Hair and Beauty has confirmed that an unauthorised person briefly accessed its online shop in August 2026. Names, emails and/or mobile numbers, plus spend and purchase-location details, were involved. The company says credit cards, bank details and home addresses were not.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
Oz Hair and Beauty customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
Here for work? Check a company domain’s exposure.
Oz Hair and Beauty has confirmed that in August 2026 an unauthorised person briefly got into the online system it uses for purchases and orders. The company told customers by email, and posted a notice on its website, around 18–20 August 2026.
It says the records involved people who bought something before August 2026: full names, email addresses and/or mobile numbers, and purchase details covering currency, total spend, and the city, state, country and postcode of the purchase. The company stated this did not include credit-card details, payment information, invoices, banking details or home addresses. It has not said how many customers were affected. It told customers it was investigating, had shut the access down with the company that hosts its online shop, and had reported the incident to the Australian Cyber Security Centre, the Office of the Australian Information Commissioner, and New Zealand’s privacy commissioner.
What “no credit cards” still leaves in someone else’s hands
Most coverage of this incident leads with what was not taken. That list is real: the company says cards, bank details and home addresses were not in what was accessed. For anyone who shops online, that sentence reads like a sigh of relief.
Read the same facts the other way. Someone who should not have this now has named customers, a way to email or call them, a postcode and city that places them, and confirmation that they shop at this store — including how much they have spent. That is not a stolen-card problem. It is an impersonation problem. A message that uses your name, mentions Oz Hair and Beauty, and talks about an order or a refund can sound ordinary, because those details are exactly what the company says were touched.
Advertisement
Know the day any company files a breach.
Every SEC 8-K Item 1.05 and state breach notification — dated, sourced, and delivered by email + a JSON API the day it posts. Track any company, not just the ones in the news.
GalaxyWarden Signals and RecentBreaches share common ownership.
A home address was not part of what the company confirmed. A full name, a postcode and a phone number or email still give a stranger a short path to you on public people-search pages and old directory listings. The missing street address is not the same thing as being hard to find.
The company has also never given a headcount. If you ordered from them before August 2026, treat the possibility as live. There is no public check that can tell you, cleanly, whether you were or were not included.
What to actually expect
- Emails or texts that pretend to be the store, a delivery firm, or a “security team” helping with this incident — especially ones that ask you to log in, confirm a payment method, or collect a refund. They may already know your name and that you shopped there.
- Calls or messages to the mobile number that was on your old orders. The company’s own notice went out around 18–20 August 2026. A later call asking you to “verify” a card or read out a code is not part of that.
- A run of ordinary-looking “account”, “policy update” or “we need you to review your order” mail to the email address you used at checkout. Some of it will be junk riding the news. Some of it may be written using the fact that you are a known customer.
- Not a wave of fraudulent card charges caused by this incident. The company has said payment information was not accessed. Unusual card activity is still worth taking seriously, but it is not what this claimed breach describes.
What you can and cannot fix
If your name, email, mobile number and those purchase and location details were in the records that were accessed, that copy is out. It cannot be recalled, taken down, or “removed” by anyone you pay. The company has not confirmed that files circulating online are a complete or accurate copy of its records — but it has confirmed the access and the fields above. That cannot be undone. There is also no public register that can prove you were spared.
- Treat unexpected contact about this shop or this incident as a scam unless you opened the real site yourself. Type the address by hand or use an app you already have. Do not use links or phone numbers from the message.
- Do not hand over card numbers, bank logins or one-time codes. The company has already said those payment details were not in this incident. Anyone who contacts you and asks for them is not fixing the breach.
- Search for yourself on people-finder and directory sites and request removal where you can. A bare record of a name, a mobile and a postcode becomes much more useful to a stranger when those sites add relatives, extra phone numbers, employers and old addresses. Unlike the copy that was accessed, those listings can actually be taken down. That is the lever that still works.
- Watch the specific inbox and mobile you used to shop there for the next few months, including the spam folder. That is where a convincing fake “order” or “refund” will arrive. You do not need a new bank account because of this incident. You do need to be slower to trust a message that already knows your name and the shop.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: get an alert the day a vendor you watch files a breach with a US regulator or the SEC — the filing itself, dated and sourced, plus an API. GalaxyWarden Signals →
A staff address in a leak usually means a third party was breached, not you — check your own domain’s exposure. Exposure Monitoring →
Report details & sourcing
Related breaches
Kindol vintage shop leak: 136,464 customers and 109,311 home addresses taken
Treasure Factory confirmed on 28 August 2026 that a phishing email let an attacker into a staff acco…
Tixel data breach: your email and mobile number may have been accessed
Tixel emailed customers on 28 August 2026 to say their email address and mobile number may have been…
Kindal data leak: 136,464 customers, names and home addresses exposed
Kindal, Treasure Factory’s second-hand brand clothing site, confirmed that a phishing email tricked …