Oz Hair and Beauty Data Breach (August 2026)
Australian beauty retailer Oz Hair and Beauty was the target of an extortion attack in August 2026 that exposed 1,988,331 customer email addresses along with names, phone numbers, suburb and postcode locations, and purchase records, according to Have I Been Pwned.
- Organization
- Oz Hair and Beauty
- Sector
- Retail
- Country
- Australia
- Incident date
- August 15, 2026
- Disclosed
- August 19, 2026
- Records affected
- 2 million
- Attack type
- Third-party breach
- Threat actor
- xpl0itrs
- Status
- Confirmed
- Email addresses
- Geographic locations
- Names
- Phone numbers
- Purchases
- A group operating as xpl0itrs lists Oz Hair and Beauty on its leak site and claims 2,100,000 customer records, as reported by Cyber Daily.
- Oz Hair and Beauty confirms the incident to Cyber Daily and says its investigation indicates the claim relates to data held by a third-party provider.
- Have I Been Pwned loads the 1,988,331 verified records and marks the breach verified, per the listing.
What Happened
Australian beauty retailer Oz Hair and Beauty was the target of an extortion attack in August 2026, per the Have I Been Pwned entry, which attributes the incident to a group operating as xpl0itrs. According to the listing, the group afterward published data it said had been taken from the company. Have I Been Pwned loaded 1,988,331 unique email addresses from that data, along with names, phone numbers, geographic locations recorded as suburb and postcode, and purchase records.
The company confirmed the incident to Cyber Daily on August 18, 2026, in an exclusive report by Daniel Croft. Oz Hair and Beauty told the publication that its investigation to date indicated the claim related to data held by a third-party provider rather than to a compromise of its own systems, and that it was working with that provider urgently to understand the nature and extent of any data affected. The provider was not named.
As reported by Cyber Daily, xpl0itrs claimed 2,100,000 customer records on its leak site, listing names, email addresses, home addresses, phone numbers and the last four digits of active gift cards. The same report describes xpl0itrs as a new group that launched in June 2026 and named Oz Hair and Beauty among its first victims. Neither the company nor Have I Been Pwned has described how the provider's data was obtained.
What Was Exposed
5 classes of data across 1,988,331 records, per Have I Been Pwned: Oz Hair and Beauty Data Breach: email addresses, geographic locations, names, phone numbers and purchases.
A name, a phone number, a home suburb and a record of what someone actually bought is the exact material an attacker needs to place a convincing scam call or text that quotes a real order back to the customer.
What to Do If You Are Affected
The full sequence, and what to do in what order, is in what to do after a data breach.
What Is Not Known Yet
Oz Hair and Beauty has not named the third-party provider, said how the data was taken, or published its own count of affected customers. Nothing public says whether Australian regulators have been notified.
Sources

Daniel Reyes
Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.
Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.