Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Oz Hair and Beauty confirms cyber incident to customers

Aussie hair and beauty business Oz Hair and Beauty has disclosed to customers that it has suffered a cyber incident.

Thu, 20 Aug 2026
Oz Hair and Beauty confirms cyber incident to customers

Earlier this week, the company was listed on the dark web leak site of a new threat actor called “xpl0itrs”, which claimed to have stolen 2,100,000 customer records containing names, email addresses, home addresses, phone numbers, and the last four digits of active gift cards.

At the time of writing, the threat actor has uploaded a link to download what it claims is the stolen data; however, the link appears to be broken.

Now, having confirmed the incident with Cyber Daily earlier in the week, Oz Hair and Beauty has informed customers of the cyber attack.

 
 

“Oz Hair and Beauty recently identified that our online purchase and order platform was briefly accessed by an unauthorised third party,” the company said in an email to customers.

“From our investigations into the incident, we are disappointed to have identified that limited personal information of yours was accessed during the incident.”

Data reportedly includes names, email addresses, phone numbers, and purchase history and details, including currency, total spend, city, state, country and postcode of purchase.

“Importantly, [the stolen data] does not include any credit card details, payment information or invoice [data],” it said.

The company said it launched an investigation into the matter upon discovery of the incident, reported the incident to the Australian Cyber Security Centre (ACSC), the Office of the Australian Information Commissioner (OAIC) and the Office of the Privacy Commissioner in New Zealand.

“Separately, we have and are undertaking steps to reduce the risk of similar events occurring moving forward. This includes reviewing and enhancing our cyber security posture and data retention policies,” it said.

Who is xpl0itrs?

Xpl0itrs is a new threat actor, or at least a new brand for a new threat group, having launched on 12 June 2026 and listing its first victim on 15 August. The group announced the launch of its dedicated leak site on 17 June.

To date, the company has five victims, including Dynatrace, BMW, RapidFort, Oz Hair and Beauty, and an unnamed Italian school management platform.

Based on reports, the group shares large amounts of tooling, victims and initial access with the TeamPCP threat group and focuses on supply chain breaches.

The group’s site said that it “no like government, like money, like freedom,” something that its most vocal member, “boxturtl”, has echoed, describing themselves as “purely for monetisation”.

Outside of what appears to be ransomware, the group sells initial access through its site. Reports also suggest it has breached a number of supply chains through compromises of Trivy, Checkmarx KICS, LiteLLM, and BitWarden CLI.

It also reportedly consistently exploited stolen PATs, OAuth tokens, and API keys to access and exfiltrate internal repository data. It then sells it to buyers as post-access enablement.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.