Skip to content
Back to Blog
medium severity August 24, 2026 · 4 min read Unverified claim — what this is

Oz Hair and Beauty data leak: what was taken and whether it affects you

If you are a customer of Oz Hair and Beauty, here’s what is being claimed, and what it would mean for you.

In August 2026 Oz Hair and Beauty confirmed that an unauthorised party briefly accessed its online purchase and order platform and obtained some customer details. Names, emails, phone numbers, suburb or postcode, and purchase history were involved; the company says credit cards, banking details and home addresses were not. That data was later published. A public breach directory listed about 2 million unique email addresses; the company has not confirmed a number.

— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Oz Hair and Beauty data leak: what was taken and whether it affects you

In mid-August 2026, Oz Hair and Beauty confirmed that its online purchase and order platform had been briefly accessed by an unauthorised third party. A spokesperson spoke to reporters on 18 August, customers were emailed around 19–20 August, and the company posted its own statement. It said the information related to purchases made before August 2026, and it first described the data as held by a third-party provider. It also said it had notified the Australian Cyber Security Centre, the Office of the Australian Information Commissioner and New Zealand’s Office of the Privacy Commissioner, and had begun an investigation with its cloud e-commerce platform provider.

Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

According to the company, what was accessed was limited: full names, email addresses, phone numbers, geographic locations (suburb and postcode, or city, state, country and postcode) and purchase details such as items bought, currency and totals. It said this did not include credit card details, payment information, invoices, banking details or home addresses. Data from the incident was then published. On 19 August 2026, Have I Been Pwned independently listed a matching dataset of about 2 million unique email addresses, with names, phone numbers, suburb and postcode, and purchases. Oz Hair and Beauty has not itself confirmed how many customers or records were affected.

The risk is a convincing scam, not a drained card

Most coverage has followed the company’s list of what was left out: no cards, no bank accounts, no home addresses. That list matters, and it matches both the company’s statements and the independent listing. It is also not the part that changes your week.

What is now in other people’s hands is a working contact list. A record can pair a real name with an email address, a phone number, a suburb or postcode, and things that person actually bought. Nobody can use this file to charge your card. They can use it to ring or email you and sound as if they already know you.

“We need to update your order” is hard to ignore when the product is real. So is a message about “your Oz Hair and Beauty data” that asks you to click, call back, or confirm something. The leaked fields are exactly the ones that make those approaches feel personal. Home addresses not being included means a stranger should not have your street and number from this incident. It does not mean they cannot reach you, or place you well enough to target you.

If you bought from this shop before August 2026, you should assume your details may be in the published set. The company emailed customers; not getting that email is not proof you were left out. Some records may also be old. There is no reliable way for an article, or a scan, to tell you whether your name is in this particular file.

What to actually expect

  • Emails or texts that mention a real-sounding order, a refund, or “your data from the Oz Hair and Beauty incident,” written to get you to click, reply, or call a number they provide.
  • Phone calls that already use your name, and may mention a suburb or a product you bought, offering help, compensation, or paid “identity monitoring.”
  • A lasting rise in ordinary spam and scam traffic to the email address and phone number that were in the file.
  • Not fraudulent card charges that come from this leak. Anyone who says you must pay to freeze a card, unlock an account, or “secure your refund” because of this incident is using the news against you.

What you can and cannot fix

If your details were in the published set, that cannot be undone. Names, email addresses, phone numbers, suburb or postcode, and purchase history that have already been copied cannot be recalled. No shop, government office or cleanup service can pull them back.

  • Treat unexpected contact about this shop, this incident, or an old order as an attempt to use the leak. The genuine customer email went out around 19–20 August 2026. A new urgent request for a password, a payment, ID documents or “verification” is not a cleanup step. It is the harm.
  • Do not add information. Someone who already has your name, phone number and a past purchase does not need you to confirm a date of birth, a full address, a licence number or a card number. That is how a limited leak is turned into a worse one.
  • Shrink the rest of your public footprint. A bare leaked record becomes much more useful when it is joined to people-search listings that add relatives, extra phone numbers, employers and previous addresses. Those listings, unlike the leaked file, can actually be removed. That is the lever you still have.
  • Watch the email address and phone number that may have been included. No password was reported stolen in this incident, so a sudden “reset your account” message is a reason to be suspicious, not a reason to follow the link.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
Oz Hair and Beauty is one listing. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity Medium contact details only, none of them permanent
Disclosed August 24, 2026
Last reviewed August 24, 2026
Affected Unconfirmed
Data exposed Full namesEmail addressesPhone numbersGeographic locations (suburb/postcode)Purchase history
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email