Oz Hair and Beauty Discloses Customer Data Breach Across Order Platform

In this article (2)
Oz Hair and Beauty has suffered a cyber incident on its online purchasing platform. The breach exposed the personal details and transaction histories of customers who placed orders before August.
An unauthorised third party gained brief access to data managed through an external service provider. The Australian e-commerce merchant disclosed the incident to shoppers in a direct notification.
Exposed records include full names, email addresses, mobile numbers, and purchase details showing total spend, currency, city, state, and postcode. Attackers did not obtain passwords, credit card numbers, payment details, or street addresses, the company stated.
Third-Party Platform Compromise
External technical specialists launched an investigation immediately after staff detected the intrusion. Early findings point to data held by a contractor rather than a direct breach of internal systems.
Oz Hair and Beauty has not disclosed the total number of affected customer accounts. It reported the incident to the Australian Cyber Security Centre and the Office of the Australian Information Commissioner while notifying affected buyers.
Earlier this month, a separate cyber attack hit furniture retailer Nick Scali and forced core IT infrastructure offline across its regional business. Australian consumer brands face tightening scrutiny over vendor data storage as regulators press merchants to shorten retention schedules.
Security Audit Underway
The beauty retailer is now overhauling its data protection controls and third-party storage policies to prevent repeat exposures across its digital channels.
Technical investigators are still determining the full timeline of the intrusion. The retailer has yet to submit its final incident report to federal privacy regulators.