Your Shampoo Order Just Leaked Your Phone Number — What to Do Now
The Oz Hair and Beauty breach exposed about 2 million Australians through a supplier, not the shop. Check if you're in it and blunt the scam calls that follow.
Published 2026-09-21
The short version
- The Oz Hair and Beauty breach exposed around 2 million unique email addresses, plus names, phone numbers, suburbs, postcodes and purchase history.
- The retailer's own platform wasn't the entry point: the breach happened at a third-party provider most customers had never heard of.
- No card data was taken, so the real risk is convincing scam calls and messages that already know your name, suburb and last order.
- The data is searchable on Have I Been Pwned. Checking takes about 20 seconds and costs nothing.
What happened in the Oz Hair and Beauty breach?
In August 2026, Australian online retailer Oz Hair and Beauty was listed by an extortion group calling itself xpl0itrs, which then published the data. The set holds around 2 million unique email addresses, along with names, phone numbers, suburb and postcode, and purchase history.
The company confirmed the incident. It said the access was brief and affected purchases made before August 2026. No credit card data was exposed. And the detail that matters most: forensic work found the breach was at a third-party provider, not on the retailer's own platform.
So the shop didn't get hacked. Its supplier did. That's the whole story, and it's worth sitting with, because it isn't a bank or a telco. It's a place you bought shampoo from.
Why did a supplier have my data in the first place?
Every business you buy from runs on suppliers you've never heard of. Payment processors, delivery and tracking services, email marketing platforms, review widgets, analytics tools, customer-service software, warehouse systems. Each of them can hold a slice of your customer record, and some hold the whole thing.
You never agreed to deal with those companies. You agreed to buy a product. But your name, phone number and order history travelled out the back door the moment you checked out, and you can't opt out of a supplier's security any more than you can inspect it.
There's an asymmetry here that privacy-minded people will recognise. If you want to know what a government agency holds about you, there's a legal process and the agency is required to answer. If you want to know which supplier your favourite online shop passed your details to, and what that supplier kept, there's usually no one to ask. You don't even know its name. The businesses that profit from moving your data around are the same ones that are hardest to question about it.
Australia's proposed Tranche 2 privacy reforms include a statutory split between "controllers" and "processors", which would put clearer obligations on the companies working behind the shopfront. The consultation closed on 18 September and no go-live date has been announced. Until then, the practical protection is on your side of the counter.
It's not "just" an email address
Breach notices love the phrase "no financial information was taken". It's true here, and it's still not reassuring.
Put the fields together: your name, your mobile number, your suburb and postcode, and what you bought. That's not a spam list. That's a script.
A scam caller who has this record can open with your first name, mention your suburb, and reference your last order by product. "Hi Sarah, it's the delivery team calling about the hair dryer you ordered, we need to confirm your address in Brunswick." Every detail checks out, because every detail is real. The only thing they need from you is the one thing they don't have, whether that's a card number, a one-time code or a click on a link.
That's why breaches like this one are dangerous even without passwords or cards in them. Accuracy is what makes a scam convincing, and a purchase history supplies accuracy in bulk.
How do I check if my details were in the breach?
The Oz Hair and Beauty data is searchable on Have I Been Pwned, a free service run by Australian security researcher Troy Hunt. It collects known breaches into one database. Type in your email address and it tells you which breaches it has appeared in, when they happened, and what kinds of data were exposed.
No account is needed and nothing is sold. It's the simplest way to answer "how much of my data is already out there?" without asking permission from the companies that leaked it.
- Go to haveibeenpwned.com and search every email address you use for online shopping, not just your main one.
- If Oz Hair and Beauty shows up, note which address it was and what data the entry says was exposed.
- Look at the other breaches listed too. Most people find a few they'd forgotten about.
- Sign up for the free breach notifications on the same site so you hear about the next one without having to check.
What to do this week
None of this needs special skills. It needs about an hour and a bit of stubbornness.
- Change the password on your Oz Hair and Beauty account, then change it anywhere else you used the same password. Assume a reused password is compromised everywhere it lives.
- Turn on multi-factor authentication for your email account first. Your inbox is the reset button for everything else.
- Expect scam calls and texts that know your order. If someone calls about a delivery, refund or "problem with your account", hang up and contact the retailer yourself using the details on its official website.
- Never read out a one-time code to anyone who called you. No legitimate business needs it.
- Report scam contact to Scamwatch, and if you think your identity is being misused, contact IDCARE, Australia's free identity and cyber support service.
No card data was taken in this breach, so you don't need to cancel your cards because of it. Keep an eye on statements anyway, as you would after any breach.
Use email aliases so you know who leaked
Here's the habit that changes the game for next time. An email alias is a separate forwarding address you create for one company. Mail sent to it lands in your normal inbox, but the company never sees your real address. Give every online shop its own alias and a breach stops being a mystery.
If spam or scam emails start arriving at the alias you gave your hair and beauty retailer, you know exactly where they came from, even if the leak happened at a supplier you've never heard of. No data request, no waiting on a reply that may never come. The evidence turns up in your inbox. Then you switch that alias off, and the leaked address dies with it.
Free services such as SimpleLogin and addy.io make this easy, with browser extensions that create a new alias at checkout. If you want an inbox built around aliases and encryption from the start, we maintain a separate site, NoSpyEmail, that goes through the private email providers that hold up to that kind of scrutiny.
Aliases don't cover your phone number, which is the more dangerous field in this breach. For that, the only real defence is the rule above: treat every unexpected call as unverified until you've called back on a number you found yourself.
Can I complain about a data breach in Australia?
Yes. Start with the company. Ask what data of yours was affected, which third party was involved, and what's being done about it. Be ready for a slow or thin answer. Honestly, that's common, and it's part of why the privacy reforms matter.
If you're not satisfied after 30 days, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC). It's free, and every complaint adds to the record regulators use when deciding where to look. If you're in the UK, the equivalent is the ICO; in the EU, your national data protection authority.
It can feel like shouting into the wind. It isn't nothing. Regulators act on patterns, and complaints are how patterns get noticed.
The bigger lesson: shop like your data travels
You can't audit every supplier behind every online shop. Nobody can. What you can do is give each shop less to lose: a unique password, a separate email alias, and no more personal detail than the order actually needs. Skip the optional birthday field. Check out as a guest where it's offered.
Then, when the next breach notice lands, and it will, you'll know which address leaked, the password won't work anywhere else, and a caller who knows your suburb won't get anything more out of you. That's quiet, steady protection, and it doesn't depend on any company getting its security right.
Frequently asked questions
Was my credit card exposed in the Oz Hair and Beauty breach?
The company says no credit card data was exposed. The data taken includes email addresses, names, phone numbers, suburb and postcode, and purchase history.
How do I know if I was affected by the Oz Hair and Beauty data breach?
Search your email address on Have I Been Pwned (haveibeenpwned.com), where the breach is listed. It's free and takes about 20 seconds.
If the retailer wasn't hacked, how did my data leak?
Forensic work found the breach happened at a third-party provider rather than on the retailer's own platform. Online shops share customer data with suppliers for things like delivery, marketing and customer service, and a breach at any of them can expose you.
What should I do if a caller mentions my recent order?
Treat it as unverified. Hang up, find the retailer's contact details on its official website, and call back yourself. Never share one-time codes or card details with someone who called you.
Where can I report a data breach in Australia?
Raise it with the company first, then lodge a complaint with the OAIC if you aren't satisfied after 30 days. Report scam calls to Scamwatch, and contact IDCARE if you suspect identity misuse.
Ready to act on this?
We've reviewed the tools so you don't have to.