Oz Hair and Beauty data breach: what was taken and what you should do
If you have an account with Oz Hair and Beauty, here’s what’s now in circulation.
Oz Hair and Beauty has confirmed that an unauthorised party accessed some customer details from its online shop. Names, emails and/or mobile numbers, and basic purchase information were involved; payment cards and passwords were not. The company is emailing affected customers and says the website is still safe to use.
Oz Hair and Beauty customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
Oz Hair and Beauty has confirmed that someone got unauthorised access, briefly, to its online purchase and order platform. The company says limited personal information of some customers was involved. For people who made purchases before August 2026, that means full name, contact information (email address and/or mobile number), and purchase data: the currency used, total spend, purchase location, and the date the customer record was created. It does not include credit card details, passwords, payment information or invoice details.
The company says it has contained the incident, is notifying affected customers by email, and has reported it to the Australian Cyber Security Centre, the Office of the Australian Information Commissioner and the New Zealand Office of the Privacy Commissioner. It has not said how many people were involved, and it has not said the data was published. Have I Been Pwned separately checked a dataset the attackers put out that matches those fields and recorded about 2 million unique email addresses in it — a figure the company has not adopted. Most of those addresses had already appeared in other known breaches. The company says the website remains safe to use. No one has denied that the access happened.
What the “no cards, no passwords” line leaves out
Almost every account of this incident leads with what was not taken. That part is true. Your card number and your password were not in what the company says was accessed, which is why this is not a reason to cancel cards or to assume someone can log in as you.
What that framing skips is what a stranger actually holds if your record was in the grab: your name, a way to email or text you, and confirmation that you shop at this store, including how much you have spent and where the purchase was recorded. That is not a bank login. It is the ingredient list for a message that sounds like customer service — a problem with an order, a refund waiting, an account that needs to be “secured.” Those notes work because they are not generic. They mention a shop you really use, and they can arrive on the same phone or inbox you used at checkout.
The company calls this limited personal information. Against the usual picture of a hack, it is limited. Against a convincing scam text this month, it is the useful part.
Advertisement
BATECH StudioWe build it.We run it.Web apps, AI pipelines and internal tools — under your brand, not ours.Tell us what you need →
BATECH Studio and GalaxyWarden share common ownership.
Two other claims circulating are weaker than they sound. The attackers said they also had home addresses and the last four digits of gift cards; the company’s statement, and later checks of the published files, do not support that. And the round number of about 2 million comes from Have I Been Pwned’s count of unique emails in a published file, not from Oz Hair and Beauty, which has only said “some customers.” We cannot tell you whether you were in this incident. If you bought there before August 2026, the notice the company has promised is an email from them — and scammers will send their own versions of that email too.
What to actually expect
- If the company believes your details were involved, it says it will email you. Treat unexpected messages about this incident with care: the real shop and copycat senders will both be using the same subject matter. A message that asks you to re-enter a card, reset a password, or click through to “secure your account” does not match what the company says was taken.
- In the coming weeks, the likely nuisance is texts and emails that mention Oz Hair and Beauty, an order, a refund, or a delivery problem, aimed at the email address or mobile number used on the online shop. That is the contact data described in the company’s own notice.
- You should not expect mystery card charges that come from this incident. Payment details were not in the information the company says was accessed.
- A published customer file matching this incident has been verified by Have I Been Pwned. The company itself has not confirmed that anything was published and has not given a headcount. Extra junk mail to an old checkout email is more likely than any formal letter from a regulator; no public regulator filing with numbers has appeared yet.
What you can and cannot fix
If your name, email, mobile number and purchase information were in the accessed records, that copy is out. It cannot be recalled, wiped from the people who took it, or reliably erased from copies that may have been passed on. Nobody can remove you from this breach.
- Treat the shop relationship as known. Do not reply to a surprise refund, delivery or “verify your account” contact with codes, card numbers or passwords. If you need to check an order, open the site yourself the way you usually do. The company says that site is still safe to use.
- Watch the inbox and the mobile number you used at checkout. That is the contact path described. You do not need new bank cards because of what the company says was taken.
- You cannot get this file unpublished. What you can reduce is the extra personal detail sitting against your name on people-search and data-broker listings — relatives, extra phone numbers, employers, previous addresses. A bare shop record becomes much more useful to a stranger when it can be joined to those listings. Unlike the stolen file, many of those listings actually let you opt out.
- If a genuine notification from the company arrives, read it. They have already told the Australian and New Zealand privacy and cyber authorities. That does not put the data back, but it is the official path if you later need to refer to the incident.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: a staff address in a leak does not mean you were breached — it usually means a third party was. We monitor a domain against 13.1B+ leaked records and tell you when one of your people appears. See what we would check →
Report details & sourcing
Related breaches
Bits of Gold data breach August 2026: was my information exposed?
On 16 August 2026, Bits of Gold said someone had unauthorized access to a supporting data-analysis s…
MyFitnessPal — 144 Million Accounts, and Whether Yours Was Safe Depended on When You Joined (2018)
MyFitnessPal used SHA-1 for older accounts and bcrypt for newer ones. Whether your password survived…
Deezer — 229 Million Records a Partner Was Supposed to Have Deleted (2019, disclosed 2022)
The music service was not breached. A third-party partner kept a mid-2019 backup after its contract …