background image blur
background image

Oz Hair & Beauty Leak: What Is Actually in the 2M+ Record File

Image of author
By Tech Writer and VPN Researcher Gintarė Mažonaitė
clock icon
Last updated: 20 August, 2026
A conceptual image of an online dabatase

Key Takeaways

  • On August 18th, 2026, a group calling itself xpl0itrs published a database claimed to be from Oz Hair & Beauty, an Australian beauty retailer; the file was mirrored on a second forum two days later.
  • Oz Hair & Beauty confirmed a cyber incident, stating its investigation indicates the data was held by an unnamed third-party provider, not its own systems.
  • A direct analysis of the file by the Mysterium VPN research team found 2,187,157 records, verified as genuine via Shopify's sequential account numbering system, with the newest signups dated July 2026.
  • Our analysis also found 24,204 records containing dates of birth embedded in a free-text notes field — a category not mentioned in the original leaker's claims or in the Have I Been Pwned listing.
An image of a database where Oz Beauty & Hair client data was leaked

Two million Australians woke up in a leaked customer database this week, and most of the coverage so far has repeated what the person who leaked it said was inside. We went and looked at the file instead.

The short version: the data is real, it is more recent than you would hope, and it contains at least one category of personal information that nobody has mentioned yet. It also contains rather less than the leaker claimed.

What Happened?

On 18th, August 2026, a group calling itself xpl0itrs published a database taken from Oz Hair & Beauty, a family-run Australian beauty retailer founded in 2012. Two days later, the file was mirrored on a second forum by a different account, which is how copies of this kind spread.

Oz Hair & Beauty has confirmed a cyber incident. Its position is that the data sits with someone else: "Our investigation to date indicates the claim relates to data held by a third-party provider." The company says it is working with that provider to establish what was affected. It has not named them.

Have I Been Pwned added the breach on 19th August, recording 2 million accounts and listing email addresses, names, phone numbers, geographic locations and purchases as the exposed data.

The File Is Genuine, and Here Is How You Can Tell

We analysed the published file directly. It holds 2,187,157 customer records with 2,004,669 unique email addresses and not a single duplicate.

The structure is a Shopify customer export, which matters because Shopify hands every customer an account number, and those numbers are issued in order across the whole platform. If a file is fabricated, those numbers do not line up with anything.

In this file, they line up perfectly. We grouped every record by the month the customer signed up, then checked whether the account numbers rose month on month. They did, in 113 out of 113 months from 2017 to 2026. We then took 100,000 random pairs of customers and asked whether the one with the lower account number had signed up earlier. The answer was yes, 100% of the time, with five exceptions in the entire sample.

Nobody fabricates that. It would mean knowing Shopify's internal numbering rate across nine years and reproducing it to the month.

The rest of the file agrees. Currency is Australian dollars on 2,168,639 records and New Zealand dollars on 18,518. The email domains are an Australian consumer fingerprint: alongside Gmail and Hotmail there are 72,190 bigpond.com addresses, 43,385 at yahoo.com.au, 15,923 at optusnet.com.au and 7,376 at iinet.net.au. Signups climb steadily from 2017 and spike in 2020, which is exactly what happened to online beauty retail during lockdown.

How Recent Is It?

Recent. The newest signups in the file are from July 2026, a matter of weeks before it was published. This is not an old archive resurfacing.

What Is in It?

  • 2,187,157 customer records;
  • 2,004,669 unique email addresses;
  • 585,986 phone numbers, of which 574,006 are Australian mobiles;
  • 1,643,632 customers in Australia, 49,243 in New Zealand;
  • New South Wales: 622,822, Victoria: 394,693, Queensland: 307,206, Western Australia: 139,903, South Australia: 96,612, ACT: 32,210, Tasmania: 31,667, Northern Territory: 8,471;
  • 1,790,581 customers with a purchase history attached, median lifetime spend A$127.80.
An image of a database where Oz Beauty & Hair client data was leaked

The Part Nobody Has Reported: DOBs

The leaker's own description lists names, emails, phone numbers, locations, and purchase history. Have I Been Pwned lists the same categories. Neither mentions dates of birth.

There are 24,204 of them in the file. They’re not in a birthday column. They’re written into a free-text notes field, in the format Birthday: 03/19/1998;, presumably typed in by staff or pulled across from a loyalty programme. Most fall between 1988 and 2000.

That matters because a date of birth is a different class of information from an email address. It’s a standard identity-verification question; it doesn’t change, and you can’t ask for a new one. Twenty-four thousand people are in that file with their birthday attached to their full name, phone number, suburb and purchase history, and as far as we can tell, none of them have been told.

The same notes field contains other things staff wrote about individual customers. Some are logistical. Some aren’t, including a handful of eBay usernames and comments about customers' behaviour. It’s a reminder that free-text boxes in retail systems end up holding things nobody intended to publish.

What's Not in It

The group said the data included home addresses and the last four digits of active gift cards. There are no gift card numbers in this file. There’s no gift card field at all.

There are no street addresses either. Location goes as far as suburb, state, and postcode. That’s still identifying when combined with a full name, but it’s not your front door, and the difference is worth knowing if you have spent the week assuming otherwise.

We mention this not to be reassuring. The file is bad enough. But if you’re deciding what to do next, it helps to know what actually leaked rather than what was advertised.

The Tags Point at the Third Party

Oz Hair & Beauty says the data was held by a third-party provider. The file offers a clue about who had access, because Shopify customer records carry tags, and the tags in this export name the apps that were writing to it.

More than 800,000 customers carry a tag from Rivo, a loyalty app, in the form Rivo VIP Tier: Oz VIP or Oz Royalty. Another 241,545 carry swell_vip_member, from Swell, an older loyalty platform, which suggests the store migrated between the two and both left traces. Nearly two million records are tagged new-nps or exisiting-nps, from a customer-survey tool. A further 120,650 carry Login with Shop.

None of that proves which provider was breached, and we are not saying it does. What it shows is how many outside services routinely hold a copy of a retailer's entire customer list. When a company says the problem sits with a third party, this is the shape of the thing they are describing.

What to Do if You Shopped There

  1. Assume your email address and phone number are public: Expect phishing that knows your name, your suburb and what you bought. That last detail is what makes these messages convincing.
  2. Be suspicious of anything about your loyalty tier: The file records who was "Oz VIP" and who was "Oz Royalty". A scam email offering to restore your points is an easy build from this data.
  3. If you gave them your birthday, treat it as compromised: Where a bank or telco lets you pick your verification questions, pick something that is not in this file.
  4. Watch for SIM-swap attempts: Half a million Australian mobile numbers sitting next to full names and purchase histories is exactly the raw material for that.
  5. Check the address on haveibeenpwned.com: The breach is listed there, so you can confirm in a few seconds rather than guessing.

The Broader Point

Nothing exotic happened here. Nobody needed a zero-day. A beauty retailer's customer list, built up over nine years and shared with a normal stack of marketing and loyalty apps, ended up in a file on a forum, and a mirror of it appeared two days later.

Most people have no idea how many companies hold a copy of their shopping history, because the relationship they think they have is with the shop. In practice, it's with the shop and everyone the shop plugged in. You cannot audit that from the outside, and you usually only find out which is which when something like this happens.

Analysis note: all figures above come from direct examination of the published file conducted by our research team. No Oz Hair & Beauty system was accessed. No personal data from the file is reproduced in this article.


Share on
Facebook share Twitter share Reddit share Linkedin share

Be part of the resistance, quietly.

Get Mysterium VPN Arrow icon
awareness campaign banner img
Image of author
Gintarė Mažonaitė
Tech Writer and VPN Researcher

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats in editorial pieces. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.

Read our editorial policy here.

Read more by this author
© Copyright 2026 UAB "MN Intelligence"