Australian magnificence retailer Oz Hair and Magnificence has confirmed a major cyber incident which will have uncovered the private information of as much as two million clients. The family-owned firm disclosed the breach to its clients on Wednesday, stating that an unauthorized third social gathering gained entry to its methods.
In an e-mail to affected people, Oz Hair and Magnificence expressed disappointment, noting that “restricted private data of yours was accessed throughout the incident.” The compromised information pertains to purchases made previous to August 2026. Particularly, the uncovered data consists of clients’ full names, e-mail addresses, and cellphone numbers. Moreover, particulars of earlier purchases, such because the gadgets purchased and the shopper’s location and postcode, have been accessed.
Crucially, the corporate has said that delicate monetary data, together with bank card particulars, cost data, and bill particulars, weren’t compromised on this cyberattack. This distinction is significant for buyer reassurance concerning monetary safety.
Investigation and Containment Efforts
Following the invention of the breach, Oz Hair and Magnificence reported taking speedy motion. The corporate initiated a complete forensic investigation and carried out containment measures. To help with these efforts, they engaged senior technical specialists from their cloud e-commerce platform supplier. This collaboration goals to know the total scope of the breach and stop additional unauthorized entry.
Darkish Net Listings and Risk Actor Claims
Stories from Cyber Each day point out that Oz Hair and Magnificence was listed on a darkish website referred to as “xpl0itrs.” This risk group claimed to have obtained roughly 2.1 million buyer information and related particulars. The “xpl0itrs” group, which reportedly launched in June 2026, asserts that it has gained entry to a number of different firms, together with distinguished names like BMW and RapidFort, along with Oz Hair and Magnificence.
Whereas the risk actor claims a particular variety of information, Oz Hair and Magnificence has not formally confirmed the precise variety of clients impacted by the cybersecurity incident. The corporate’s official statements deal with the forms of information accessed moderately than a definitive buyer depend, emphasizing the continued nature of their investigation.
Regulatory Notifications and Future Safety Enhancements
Oz Hair and Magnificence has proactively reported the incident to related authorities. These embody the Australian Cyber Safety Centre, the Workplace of the Australian Data Commissioner, and New Zealand’s Workplace of the Privateness Commissioner. This transparency with regulatory our bodies is a normal process following vital information breaches and demonstrates a dedication to compliance.
Trying forward, the corporate has dedicated to strengthening its safety measures to mitigate the chance of future incidents. “Individually, we’ve and are endeavor steps to cut back the chance of comparable occasions occurring shifting ahead,” the corporate said. This features a thorough overview and enhancement of their general cybersecurity posture and their information retention insurance policies. The purpose is to make sure that buyer information is healthier protected towards evolving cyber threats.
What Clients Ought to Do
Whereas bank card and cost particulars weren’t compromised, clients whose private data was accessed are suggested to stay vigilant. It is suggested to observe e-mail accounts for any suspicious exercise and be cautious of phishing makes an attempt which will use the accessed private particulars to attempt to trick people into revealing extra delicate data. Altering passwords for on-line accounts, particularly if the identical password is used throughout a number of companies, can also be a prudent step.
The corporate’s dedication to enhancing its safety protocols suggests a long-term technique to rebuild buyer belief. The incident serves as a stark reminder of the persistent threats confronted by companies of all sizes and the crucial significance of strong cybersecurity measures within the digital age.

