Utah Gun Exchange
July 17, 2020
•[ hack, misconfiguration, retail ]
In July 2020, the Utah Gun Exchange website suffered a data breach which included several other associated websites. In total, 235k unique email addresses were exposed before being traded online alongside names, usernames, genders, IP addresses and password hashes. The data was provided to HIBP by breachbase.pw.
WiziShop
July 14, 2020
•[ leak, retail ]
In July 2020, the French e-commerce platform WiziShop suffered a data breach. The breach exposed 18GB worth of data including names, phone numbers, dates of birth, physical and IP addresses, SHA-1 password hashes and almost 3 million unique email addresses. The data was provided to HIBP by a source who requested it be attributed to "pom@pompur.in".
Drizly
July 2, 2020
•[ hack, retail ]
In approximately July 2020, the US-based online alcohol delivery service Drizly suffered a data breach. The data was sold online before being extensively redistributed and contained 2.5 million unique email addresses alongside names, physical and IP addresses, phone numbers, dates of birth and passwords stored as bcrypt hashes. The data was provided to HIBP by dehashed.com.
Havenly
June 25, 2020
•[ leak, retail ]
In June 2020, the interior design website Havenly suffered a data breach which impacted almost 1.4 million members of the service. The exposed data included email addresses, names, phone numbers, geographic locations and passwords stored as SHA-1 hashes, all of which was subsequently shared extensively throughout online hacking communities. The data was provided to HIBP by dehashed.com.
LiveAuctioneers
June 19, 2020
•[ leak, misconfiguration, retail ]
In June 2020, the online antiques marketplace LiveAuctioneers suffered a data breach which was subsequently sold online then extensively redistributed in the hacking community. The data contained 3.4 million records including names, email and IP addresses, physical addresses, phones numbers and passwords stored as unsalted MD5 hashes. The data was provided to HIBP by breachbase.pw.
Claire's
June 15, 2020
•[ financial, malware, retail ]
Researchers from Sansec reveal that the websites for U.S. based jewelry and accessory giant Claire's, and its subsidiary Icing, were compromised in April via a Magecart attack.
In Sport
June 11, 2020
•[ ransomware, malware, retail ]
Activewear retailer In Sport reveals to have suffered a Sodinokibi ransomware attack back in May 2020.
Avon
June 8, 2020
•[ ransomware, malware, retail ]
Cosmetics giant Avon discloses a security incident allegedly due to the DoppelPaymer ransomware.
Teespring
June 1, 2020
•[ leak, retail ]
A hacker has leaked the details of millions of users registered on Teespring, a web portal that lets users create and sell custom-printed apparel.
Neiman Marcus
May 30, 2020
•[ leak, retail ]
Neiman Marcus suffers a data breach compromising personal information of approximately 4.6 million customers.
Minted
May 9, 2020
•[ leak, retail ]
Minted, an online marketplace of independent artists and designers, suffers 5 million accounts leaked by ShinyHunters.
Bhinneka
May 9, 2020
•[ leak, retail ]
Bhinneka has 1.2 million records dumped by ShinyHunters.
HomeChef
May 8, 2020
•[ leak, misconfiguration, retail ]
A database with 8 million records belonging to the meal kit delivery service HomeChef is put on sale on the dark web.
StorEnvy
May 7, 2020
•[ leak, hack, retail ]
The e-commerce website StorEnvy is hacked and as a result, personal details of over 1.5 million customers and merchants are leaked online.
Bukalapak
May 4, 2020
•[ leak, retail ]
The data of 13 million users of the e-commerce platform Bukalapak are posted on a dark web forum, despite the company denying the breach.
Harvest Sherwood Food Distributors
May 3, 2020
•[ ransomware, malware, retail ]
Food supplier Harvest Sherwood Food Distributors is hit by a REvil ransomware attack.
Tokopedia
May 3, 2020
•[ hack, brute-force, retail ]
A hacker sells a database containing the information of 91 million Tokopedia accounts on a dark web market for $5,000. Other threat actors start to crack passwords and share them online.
Robert Dyas
April 26, 2020
•[ financial, malware, retail ]
Robert Dyas notifies customers to have been hit by a malicious script in the payment page between 7-30 March.
Whisky Auctioneer
April 21, 2020
•[ hack, ddos, retail ]
An online auction of rare whiskies is postponed indefinitely following a DDoS attack.
PrimoHoagies
April 17, 2020
•[ financial, retail ]
PrimoHoagies reveals that cyber-attackers had broken into its online payment platform and accessed the payment card information of customers who made online purchases between July 15, 2019, and February 18, 2020.