Skip to content
Fashion

Sephora data breach impacts APAC consumers

By Aiko Tanaka
1 min read
sephora
sephora
In this article (5)

A Sephora data breach has been confirmed, spanning customers from Hong Kong across Southeast Asia and into Australasia.

The LVMH-owned company has emailed online customers who may have been affected confirming some of their data may have been accessed and copied.

The international beauty retailer said an unknown number of customers have been affected in territories including Hong Kong, Singapore, Malaysia, Indonesia, Thailand, the Philippines, New Zealand and Australia. Stores were not affected with the compromised data relating only to people using the brand’s online services in the region.

The firm sent an email out to its users on Monday explaining that the breach had become apparent over the course of the past fortnight.

“Some personal information may have been exposed to unauthorized third parties,” said the email signed by Sephora’s MD Southeast Asia Alia Gogi, “including first and last name, date of birth, gender, email address and encrypted password, as well as data related to beauty preferences.”

The email (pictured above) explaining the Sephora data breach stated that credit card information does not appear to have been accessed and that personal data had not been misused.

The firm has responded by resetting all existing passwords and conducting a full security review, as well as offering customers a free personal monitoring service, available via a unique code and sign-up link directing users to a third party solutions provider.

Questions & Answers

Q.

Which specific regions and countries are affected by this data breach?

A.

The breach impacts customers from Hong Kong, Singapore, Malaysia, Indonesia, Thailand, the Philippines, New Zealand, and Australia. The affected region spans across Southeast Asia and into Australasia, as well as Hong Kong.

Q.

What types of customer data were potentially exposed during this incident?

A.

Potentially exposed data includes customers' first and last names, date of birth, gender, email address, and encrypted passwords. Information related to beauty preferences may also have been accessed by unauthorised parties.

Q.

What actions has Sephora taken in response to discovering the data breach?

A.

Sephora has reset all existing customer passwords and is conducting a full security review. The company is also offering affected customers a free personal monitoring service through a third-party solutions provider.

Q.

Was any financial or credit card information compromised in this data breach?

A.

No, the company has stated that credit card information does not appear to have been accessed. The breach primarily concerns personal details and encrypted passwords, not financial data.

Reader pulse

Sephora's data breach response:

17,792 votes so far

Weekly Briefing

Asia's retail intelligence, in your inbox

Monday, Wednesday and a Friday Weekly Wrap: the retail stories, numbers and moves that mattered across Asia. Nothing else, and you can unsubscribe in one click.

  • Top industry moves and market shifts
  • Weekly data-driven analysis from across Asia
  • Monday, Wednesday and the Friday Weekly Wrap

Read by retail operators, investors and brand teams across Asia.

Protected by a quick human check. No spam, ever. Unsubscribe in one click.

SecureGDPR ready