Skip to content
Back to Blog
medium severity August 24, 2026 · 4 min read Unverified claim — what this is

Oz Hair and Beauty data breach: what was taken and what to do now

If you are a customer of Oz Hair and Beauty, here’s what is being claimed, and what it would mean for you.

Oz Hair and Beauty has confirmed that an unauthorised person briefly accessed its online shop in August 2026. Names, emails and/or mobile numbers, plus spend and purchase-location details, were involved. The company says credit cards, bank details and home addresses were not.

— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Oz Hair and Beauty data breach: what was taken and what to do now

Oz Hair and Beauty has confirmed that in August 2026 an unauthorised person briefly got into the online system it uses for purchases and orders. The company told customers by email, and posted a notice on its website, around 18–20 August 2026.

Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

It says the records involved people who bought something before August 2026: full names, email addresses and/or mobile numbers, and purchase details covering currency, total spend, and the city, state, country and postcode of the purchase. The company stated this did not include credit-card details, payment information, invoices, banking details or home addresses. It has not said how many customers were affected. It told customers it was investigating, had shut the access down with the company that hosts its online shop, and had reported the incident to the Australian Cyber Security Centre, the Office of the Australian Information Commissioner, and New Zealand’s privacy commissioner.

What “no credit cards” still leaves in someone else’s hands

Most coverage of this incident leads with what was not taken. That list is real: the company says cards, bank details and home addresses were not in what was accessed. For anyone who shops online, that sentence reads like a sigh of relief.

Read the same facts the other way. Someone who should not have this now has named customers, a way to email or call them, a postcode and city that places them, and confirmation that they shop at this store — including how much they have spent. That is not a stolen-card problem. It is an impersonation problem. A message that uses your name, mentions Oz Hair and Beauty, and talks about an order or a refund can sound ordinary, because those details are exactly what the company says were touched.

A home address was not part of what the company confirmed. A full name, a postcode and a phone number or email still give a stranger a short path to you on public people-search pages and old directory listings. The missing street address is not the same thing as being hard to find.

The company has also never given a headcount. If you ordered from them before August 2026, treat the possibility as live. There is no public check that can tell you, cleanly, whether you were or were not included.

What to actually expect

  • Emails or texts that pretend to be the store, a delivery firm, or a “security team” helping with this incident — especially ones that ask you to log in, confirm a payment method, or collect a refund. They may already know your name and that you shopped there.
  • Calls or messages to the mobile number that was on your old orders. The company’s own notice went out around 18–20 August 2026. A later call asking you to “verify” a card or read out a code is not part of that.
  • A run of ordinary-looking “account”, “policy update” or “we need you to review your order” mail to the email address you used at checkout. Some of it will be junk riding the news. Some of it may be written using the fact that you are a known customer.
  • Not a wave of fraudulent card charges caused by this incident. The company has said payment information was not accessed. Unusual card activity is still worth taking seriously, but it is not what this claimed breach describes.

What you can and cannot fix

If your name, email, mobile number and those purchase and location details were in the records that were accessed, that copy is out. It cannot be recalled, taken down, or “removed” by anyone you pay. The company has not confirmed that files circulating online are a complete or accurate copy of its records — but it has confirmed the access and the fields above. That cannot be undone. There is also no public register that can prove you were spared.

  • Treat unexpected contact about this shop or this incident as a scam unless you opened the real site yourself. Type the address by hand or use an app you already have. Do not use links or phone numbers from the message.
  • Do not hand over card numbers, bank logins or one-time codes. The company has already said those payment details were not in this incident. Anyone who contacts you and asks for them is not fixing the breach.
  • Search for yourself on people-finder and directory sites and request removal where you can. A bare record of a name, a mobile and a postcode becomes much more useful to a stranger when those sites add relatives, extra phone numbers, employers and old addresses. Unlike the copy that was accessed, those listings can actually be taken down. That is the lever that still works.
  • Watch the specific inbox and mobile you used to shop there for the next few months, including the spam folder. That is where a convincing fake “order” or “refund” will arrive. You do not need a new bank account because of this incident. You do need to be slower to trust a message that already knows your name and the shop.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
Oz Hair and Beauty is one listing. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity Medium contact details only, none of them permanent
Disclosed August 24, 2026
Last reviewed August 24, 2026
Affected Unconfirmed
Data exposed Full namesEmail addressesMobile phone numbersPurchase historyCityStateCountryPostcode
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email