Oz Hair and Beauty data leak: what was taken and what to do now
If you are a customer of Oz Hair and Beauty, here’s what is being claimed, and what it would mean for you.
In mid-August 2026 Oz Hair and Beauty confirmed that an attacker accessed its online order platform and a customer file was later published. Names, emails, phone numbers, purchase history and suburb-level location details were involved. The company says payment cards and home addresses were not.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
Oz Hair and Beauty customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
Here for work? Check a company domain’s exposure.
In mid-August 2026, Australian beauty retailer Oz Hair and Beauty confirmed that an unauthorised party briefly accessed its online purchase-and-order platform. That confirmation came in emails the company sent to customers and in comments its spokespersons gave to journalists. There is no statement on the company’s own website. It says it reported the matter to the Australian Cyber Security Centre, the Office of the Australian Information Commissioner, and New Zealand’s privacy regulator. Those agencies have not issued a public statement of their own about this incident.
The incident became public around 18 August 2026, when an extortion group listed the company and published a customer file. Have I Been Pwned independently counted about 2 million unique email addresses in that file; a related count is 1,988,331 accounts. The attackers claimed 2.1 million records. The company itself has never given a number. It says the information relates to purchases made before August 2026 and includes full names, email addresses, phone numbers, purchase-history details (items bought, currency, total spend), and location information such as city, state, country, suburb and postcode. It says credit-card details, payment information, invoices, banking details and home addresses were not involved, and that its website does not store card data.
Why “limited information” is not the same as nothing useful
Most coverage has repeated the company’s phrasing: the data was “limited,” cards were not taken, street addresses were not taken. Those points are true on the What's Publicly Reported, and they are better news than many retail incidents. They are also not the part that changes how you should treat a phone call or an email next week.
Advertisement
BATECH StudioWe build it.We run it.Web apps, AI pipelines and internal tools — under your brand, not ours.Tell us what you need →
BATECH Studio and GalaxyWarden share common ownership.
What the published file actually gives someone is a named contact list with a receipt attached. For anyone in that file, a stranger can know your name, email you, ring you, place you in a suburb or postcode, and refer to things you actually bought and what you spent. That is how a message stops looking like junk and starts looking like the shop. The company is right that this is not a dump of payment cards. The honest read for a customer is simpler: it is enough for someone to pretend they are the shop, using details only the shop should have.
The attackers also claimed home addresses and the last four digits of gift cards. The company has explicitly said home addresses were not leaked. Gift-card digits remain unconfirmed. “Not your street address” is not the same as “they do not know where you are.” A full name plus a suburb or postcode is already enough, in much of Australia and New Zealand, to pick one household out of a search result — especially once it is sitting next to the phone number from the same file.
If you placed an online order with Oz Hair and Beauty before August 2026, assume this may include you. The company has not published a list or a headcount, and nobody can honestly tick your name off a public checklist for you.
What to actually expect
- Emails or texts that mention an Oz Hair and Beauty order, a refund, a gift card, or this incident, and ask you to click, log in, or call a number they provide.
- Phone calls from people who already use your name and already know you shopped there. That knowledge comes from the file; it is not proof they work for the shop.
- The published file will keep being copied. It will not be pulled back, and later copies will not look any more official than the first one.
- A genuine customer email from the company already went out around 20 August 2026. New messages after that claiming to “help” you with the incident are the ones to treat as hostile.
What you can and cannot fix
If your name, email address, phone number, order history and suburb or postcode were in the published file, that combination is out. It cannot be recalled, taken down, or made private again. Anyone who copied the file still has it.
On the What's Publicly Reported, this is not a reason to cancel cards or treat your street address as newly published. The company says those were not in what was taken.
- Do not reply to, click, or call back any unexpected message about an order or this incident. If you need to check an order, open the shop’s website yourself by typing it — do not use a link in the message.
- If a caller already knows what you bought, hang up. Knowing your order is exactly what this file provides.
- Cut down people-search and data-broker listings under your name. A bare leaked record is a name, a phone, an email, a suburb and a shopping list. It becomes much more dangerous when a public listing adds relatives, an employer and previous addresses. Those listings, unlike the leaked file, can actually be removed.
- Treat any request for money, a card number, a gift-card code, or a password as the scam, not the cleanup. Payment data was not part of this incident on the company’s account.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: a staff address in a leak does not mean you were breached — it usually means a third party was. We monitor a domain against 13.1B+ leaked records and tell you when one of your people appears. See what we would check →
Report details & sourcing
Related breaches
Oz Hair and Beauty data breach: what was taken and what you should do
Oz Hair and Beauty has confirmed that an unauthorised party accessed some customer details from its …
Origin Energy data breach: were my details in the 900,000 affected?
Origin Energy has confirmed that about 900,000 current and former customers had personal information…
Was I in the SafePal data breach? What they took and what they didn't
On 16 August 2026 SafePal said a flaw in its order-tracking plug-in exposed names, emails, shipping …