Skip to content
Cyber Security Firms
ConfirmedRetail

Oz Hair and Beauty Data Breach (August 2026)

Australian beauty retailer Oz Hair and Beauty was the target of an extortion attack in August 2026 that exposed 1,988,331 customer email addresses along with names, phone numbers, suburb and postcode locations, and purchase records, according to Have I Been Pwned.

Disclosed Updated
Organization
Oz Hair and Beauty
Sector
Retail
Country
Australia
Incident date
August 15, 2026
Disclosed
August 19, 2026
Records affected
2 million
Threat actor
xpl0itrs
Status
Confirmed
Data exposed
  • Email addresses
  • Geographic locations
  • Names
  • Phone numbers
  • Purchases
Timeline
  1. A group operating as xpl0itrs lists Oz Hair and Beauty on its leak site and claims 2,100,000 customer records, as reported by Cyber Daily.
  2. Oz Hair and Beauty confirms the incident to Cyber Daily and says its investigation indicates the claim relates to data held by a third-party provider.
  3. Have I Been Pwned loads the 1,988,331 verified records and marks the breach verified, per the listing.

What Happened

Australian beauty retailer Oz Hair and Beauty was the target of an extortion attack in August 2026, per the Have I Been Pwned entry, which attributes the incident to a group operating as xpl0itrs. According to the listing, the group afterward published data it said had been taken from the company. Have I Been Pwned loaded 1,988,331 unique email addresses from that data, along with names, phone numbers, geographic locations recorded as suburb and postcode, and purchase records.

The company confirmed the incident to Cyber Daily on August 18, 2026, in an exclusive report by Daniel Croft. Oz Hair and Beauty told the publication that its investigation to date indicated the claim related to data held by a third-party provider rather than to a compromise of its own systems, and that it was working with that provider urgently to understand the nature and extent of any data affected. The provider was not named.

As reported by Cyber Daily, xpl0itrs claimed 2,100,000 customer records on its leak site, listing names, email addresses, home addresses, phone numbers and the last four digits of active gift cards. The same report describes xpl0itrs as a new group that launched in June 2026 and named Oz Hair and Beauty among its first victims. Neither the company nor Have I Been Pwned has described how the provider's data was obtained.

What Was Exposed

5 classes of data across 1,988,331 records, per Have I Been Pwned: Oz Hair and Beauty Data Breach: email addresses, geographic locations, names, phone numbers and purchases.

A name, a phone number, a home suburb and a record of what someone actually bought is the exact material an attacker needs to place a convincing scam call or text that quotes a real order back to the customer.

What to Do If You Are Affected

The full sequence, and what to do in what order, is in what to do after a data breach.

What Is Not Known Yet

Oz Hair and Beauty has not named the third-party provider, said how the data was taken, or published its own count of affected customers. Nothing public says whether Australian regulators have been notified.

Sources

  1. Have I Been Pwned: Oz Hair and Beauty Data Breach
  2. Cyber Daily, "Exclusive: Oz Hair and Beauty confirms cyber incident," by Daniel Croft, August 18, 2026
On this page
Reviewed by

Daniel Reyes

  • CISSP
  • 12 years in security operations
  • Austin, TX

Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.

Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.

Read the full bio and how we research →