Oz Hair and Beauty data leak: what was taken and whether it affects you
If you are a customer of Oz Hair and Beauty, here’s what is being claimed, and what it would mean for you.
In August 2026 Oz Hair and Beauty confirmed that an unauthorised party briefly accessed its online purchase and order platform and obtained some customer details. Names, emails, phone numbers, suburb or postcode, and purchase history were involved; the company says credit cards, banking details and home addresses were not. That data was later published. A public breach directory listed about 2 million unique email addresses; the company has not confirmed a number.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
Oz Hair and Beauty customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
Here for work? Check a company domain’s exposure.
In mid-August 2026, Oz Hair and Beauty confirmed that its online purchase and order platform had been briefly accessed by an unauthorised third party. A spokesperson spoke to reporters on 18 August, customers were emailed around 19–20 August, and the company posted its own statement. It said the information related to purchases made before August 2026, and it first described the data as held by a third-party provider. It also said it had notified the Australian Cyber Security Centre, the Office of the Australian Information Commissioner and New Zealand’s Office of the Privacy Commissioner, and had begun an investigation with its cloud e-commerce platform provider.
According to the company, what was accessed was limited: full names, email addresses, phone numbers, geographic locations (suburb and postcode, or city, state, country and postcode) and purchase details such as items bought, currency and totals. It said this did not include credit card details, payment information, invoices, banking details or home addresses. Data from the incident was then published. On 19 August 2026, Have I Been Pwned independently listed a matching dataset of about 2 million unique email addresses, with names, phone numbers, suburb and postcode, and purchases. Oz Hair and Beauty has not itself confirmed how many customers or records were affected.
The risk is a convincing scam, not a drained card
Most coverage has followed the company’s list of what was left out: no cards, no bank accounts, no home addresses. That list matters, and it matches both the company’s statements and the independent listing. It is also not the part that changes your week.
Advertisement
Know the day any company files a breach.
Every SEC 8-K Item 1.05 and state breach notification — dated, sourced, and delivered by email + a JSON API the day it posts. Track any company, not just the ones in the news.
GalaxyWarden Signals and RecentBreaches share common ownership.
What is now in other people’s hands is a working contact list. A record can pair a real name with an email address, a phone number, a suburb or postcode, and things that person actually bought. Nobody can use this file to charge your card. They can use it to ring or email you and sound as if they already know you.
“We need to update your order” is hard to ignore when the product is real. So is a message about “your Oz Hair and Beauty data” that asks you to click, call back, or confirm something. The leaked fields are exactly the ones that make those approaches feel personal. Home addresses not being included means a stranger should not have your street and number from this incident. It does not mean they cannot reach you, or place you well enough to target you.
If you bought from this shop before August 2026, you should assume your details may be in the published set. The company emailed customers; not getting that email is not proof you were left out. Some records may also be old. There is no reliable way for an article, or a scan, to tell you whether your name is in this particular file.
What to actually expect
- Emails or texts that mention a real-sounding order, a refund, or “your data from the Oz Hair and Beauty incident,” written to get you to click, reply, or call a number they provide.
- Phone calls that already use your name, and may mention a suburb or a product you bought, offering help, compensation, or paid “identity monitoring.”
- A lasting rise in ordinary spam and scam traffic to the email address and phone number that were in the file.
- Not fraudulent card charges that come from this leak. Anyone who says you must pay to freeze a card, unlock an account, or “secure your refund” because of this incident is using the news against you.
What you can and cannot fix
If your details were in the published set, that cannot be undone. Names, email addresses, phone numbers, suburb or postcode, and purchase history that have already been copied cannot be recalled. No shop, government office or cleanup service can pull them back.
- Treat unexpected contact about this shop, this incident, or an old order as an attempt to use the leak. The genuine customer email went out around 19–20 August 2026. A new urgent request for a password, a payment, ID documents or “verification” is not a cleanup step. It is the harm.
- Do not add information. Someone who already has your name, phone number and a past purchase does not need you to confirm a date of birth, a full address, a licence number or a card number. That is how a limited leak is turned into a worse one.
- Shrink the rest of your public footprint. A bare leaked record becomes much more useful when it is joined to people-search listings that add relatives, extra phone numbers, employers and previous addresses. Those listings, unlike the leaked file, can actually be removed. That is the lever you still have.
- Watch the email address and phone number that may have been included. No password was reported stolen in this incident, so a sudden “reset your account” message is a reason to be suspicious, not a reason to follow the link.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: get an alert the day a vendor you watch files a breach with a US regulator or the SEC — the filing itself, dated and sourced, plus an API. GalaxyWarden Signals →
A staff address in a leak usually means a third party was breached, not you — check your own domain’s exposure. Exposure Monitoring →
Report details & sourcing
Related breaches
Tixel data breach: your email and mobile number may have been accessed
Tixel emailed customers on 28 August 2026 to say their email address and mobile number may have been…
Kindol vintage shop leak: 136,464 customers and 109,311 home addresses taken
Treasure Factory confirmed on 28 August 2026 that a phishing email let an attacker into a staff acco…
Eastlink data breach August 2026: what the customer emails actually mean
Eastlink emailed some current and former customers on 28 August 2026 about accounts that may have be…