Drizly
July 2, 2020
•[ hack, retail ]
In approximately July 2020, the US-based online alcohol delivery service Drizly suffered a data breach. The data was sold online before being extensively redistributed and contained 2.5 million unique email addresses alongside names, physical and IP addresses, phone numbers, dates of birth and passwords stored as bcrypt hashes. The data was provided to HIBP by dehashed.com.
Havenly
June 25, 2020
•[ leak, retail ]
In June 2020, the interior design website Havenly suffered a data breach which impacted almost 1.4 million members of the service. The exposed data included email addresses, names, phone numbers, geographic locations and passwords stored as SHA-1 hashes, all of which was subsequently shared extensively throughout online hacking communities. The data was provided to HIBP by dehashed.com.
LiveAuctioneers
June 19, 2020
•[ leak, misconfiguration, retail ]
In June 2020, the online antiques marketplace LiveAuctioneers suffered a data breach which was subsequently sold online then extensively redistributed in the hacking community. The data contained 3.4 million records including names, email and IP addresses, physical addresses, phones numbers and passwords stored as unsalted MD5 hashes. The data was provided to HIBP by breachbase.pw.
Claire's
June 15, 2020
•[ financial, malware, retail ]
Researchers from Sansec reveal that the websites for U.S. based jewelry and accessory giant Claire's, and its subsidiary Icing, were compromised in April via a Magecart attack.
In Sport
June 11, 2020
•[ ransomware, malware, retail ]
Activewear retailer In Sport reveals to have suffered a Sodinokibi ransomware attack back in May 2020.
Avon
June 8, 2020
•[ ransomware, malware, retail ]
Cosmetics giant Avon discloses a security incident allegedly due to the DoppelPaymer ransomware.
Teespring
June 1, 2020
•[ leak, retail ]
A hacker has leaked the details of millions of users registered on Teespring, a web portal that lets users create and sell custom-printed apparel.
Neiman Marcus
May 30, 2020
•[ leak, retail ]
Neiman Marcus suffers a data breach compromising personal information of approximately 4.6 million customers.
Minted
May 9, 2020
•[ leak, retail ]
Minted, an online marketplace of independent artists and designers, suffers 5 million accounts leaked by ShinyHunters.
Bhinneka
May 9, 2020
•[ leak, retail ]
Bhinneka has 1.2 million records dumped by ShinyHunters.
HomeChef
May 8, 2020
•[ leak, misconfiguration, retail ]
A database with 8 million records belonging to the meal kit delivery service HomeChef is put on sale on the dark web.
StorEnvy
May 7, 2020
•[ leak, hack, retail ]
The e-commerce website StorEnvy is hacked and as a result, personal details of over 1.5 million customers and merchants are leaked online.
Bukalapak
May 4, 2020
•[ leak, retail ]
The data of 13 million users of the e-commerce platform Bukalapak are posted on a dark web forum, despite the company denying the breach.
Harvest Sherwood Food Distributors
May 3, 2020
•[ ransomware, malware, retail ]
Food supplier Harvest Sherwood Food Distributors is hit by a REvil ransomware attack.
Tokopedia
May 3, 2020
•[ hack, brute-force, retail ]
A hacker sells a database containing the information of 91 million Tokopedia accounts on a dark web market for $5,000. Other threat actors start to crack passwords and share them online.
Robert Dyas
April 26, 2020
•[ financial, malware, retail ]
Robert Dyas notifies customers to have been hit by a malicious script in the payment page between 7-30 March.
Whisky Auctioneer
April 21, 2020
•[ hack, ddos, retail ]
An online auction of rare whiskies is postponed indefinitely following a DDoS attack.
PrimoHoagies
April 17, 2020
•[ financial, retail ]
PrimoHoagies reveals that cyber-attackers had broken into its online payment platform and accessed the payment card information of customers who made online purchases between July 15, 2019, and February 18, 2020.
Tokopedia
April 17, 2020
•[ leak, retail ]
In April 2020, Indonesia's largest online store Tokopedia suffered a data breach. The incident resulted in 15M rows of data being posted to a popular hacking forum. An additional 76M rows were later provided to HIBP in July 2020. In total, the data included over 71M unique email addresses alongside names, genders, birth dates and passwords stored as SHA2-384 hashes.
Quidd
April 10, 2020
•[ leak, retail ]
Quidd, an online marketplace for trading stickers, cards, toys, and other collectibles, appears to have suffered a data breach in 2019, and the details of around four million users are now being shared for free on underground hacking forums.