Oz Hair and Beauty data leak: what was taken and what to do now
If you are a customer of Oz Hair and Beauty, here’s what is being claimed, and what it would mean for you.
In mid-August 2026 Oz Hair and Beauty confirmed that an attacker accessed its online order platform and a customer file was later published. Names, emails, phone numbers, purchase history and suburb-level location details were involved. The company says payment cards and home addresses were not.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
In mid-August 2026, Australian beauty retailer Oz Hair and Beauty confirmed that an unauthorised party briefly accessed its online purchase-and-order platform. That confirmation came in emails the company sent to customers and in comments its spokespersons gave to journalists. There is no statement on the company’s own website. It says it reported the matter to the Australian Cyber Security Centre, the Office of the Australian Information Commissioner, and New Zealand’s privacy regulator. Those agencies have not issued a public statement of their own about this incident.
The incident became public around 18 August 2026, when an extortion group listed the company and published a customer file. Have I Been Pwned independently counted about 2 million unique email addresses in that file; a related count is 1,988,331 accounts. The attackers claimed 2.1 million records. The company itself has never given a number. It says the information relates to purchases made before August 2026 and includes full names, email addresses, phone numbers, purchase-history details (items bought, currency, total spend), and location information such as city, state, country, suburb and postcode. It says credit-card details, payment information, invoices, banking details and home addresses were not involved, and that its website does not store card data.
- Every indexed leak tied to your address — all of them, named and dated
- A deeper search of collected breach data — the kinds of your information it holds, where it finds you
- What this kind of incident typically exposes
- A ten-minute lock list written for this kind of organisation
Why “limited information” is not the same as nothing useful
Most coverage has repeated the company’s phrasing: the data was “limited,” cards were not taken, street addresses were not taken. Those points are true on the What's Publicly Reported, and they are better news than many retail incidents. They are also not the part that changes how you should treat a phone call or an email next week.
What the published file actually gives someone is a named contact list with a receipt attached. For anyone in that file, a stranger can know your name, email you, ring you, place you in a suburb or postcode, and refer to things you actually bought and what you spent. That is how a message stops looking like junk and starts looking like the shop. The company is right that this is not a dump of payment cards. The honest read for a customer is simpler: it is enough for someone to pretend they are the shop, using details only the shop should have.
The attackers also claimed home addresses and the last four digits of gift cards. The company has explicitly said home addresses were not leaked. Gift-card digits remain unconfirmed. “Not your street address” is not the same as “they do not know where you are.” A full name plus a suburb or postcode is already enough, in much of Australia and New Zealand, to pick one household out of a search result — especially once it is sitting next to the phone number from the same file.
If you placed an online order with Oz Hair and Beauty before August 2026, assume this may include you. The company has not published a list or a headcount, and nobody can honestly tick your name off a public checklist for you.
What to actually expect
- Emails or texts that mention an Oz Hair and Beauty order, a refund, a gift card, or this incident, and ask you to click, log in, or call a number they provide.
- Phone calls from people who already use your name and already know you shopped there. That knowledge comes from the file; it is not proof they work for the shop.
- The published file will keep being copied. It will not be pulled back, and later copies will not look any more official than the first one.
- A genuine customer email from the company already went out around 20 August 2026. New messages after that claiming to “help” you with the incident are the ones to treat as hostile.
What you can and cannot fix
If your name, email address, phone number, order history and suburb or postcode were in the published file, that combination is out. It cannot be recalled, taken down, or made private again. Anyone who copied the file still has it.
On the What's Publicly Reported, this is not a reason to cancel cards or treat your street address as newly published. The company says those were not in what was taken.
- Do not reply to, click, or call back any unexpected message about an order or this incident. If you need to check an order, open the shop’s website yourself by typing it — do not use a link in the message.
- If a caller already knows what you bought, hang up. Knowing your order is exactly what this file provides.
- Cut down people-search and data-broker listings under your name. A bare leaked record is a name, a phone, an email, a suburb and a shopping list. It becomes much more dangerous when a public listing adds relatives, an employer and previous addresses. Those listings, unlike the leaked file, can actually be removed.
- Treat any request for money, a card number, a gift-card code, or a password as the scam, not the cleanup. Payment data was not part of this incident on the company’s account.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
Report details & sourcing
Related breaches
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…
IDMerit AI Identity Verification MongoDB Leak — February 2026
A misconfigured MongoDB instance exposed identity-verification records — government IDs, selfies, bi…
Epstein Files Inadequate Redactions Leak — February 2026
Inadequate redactions in publicly released Epstein-related court files exposed victim names and phot…