North Queensland Cyber Watch: Oz Hair & Beauty confirms customer data was accessed
This is the sixth entry in North Queensland Cyber Watch, an ongoing series looking at cyber security incidents that affect our region and what organisations here can take from them.
Like the recent Nick Scali incident, this one happened in a national retail platform rather than a system physically located in North Queensland. It is still local in a practical sense. Oz Hair & Beauty opened its first North Queensland store at Willows Shopping Centre in Townsville on 2 July 2026, bringing a brand many locals previously dealt with online into the local retail landscape.
The company has now confirmed that an unauthorised third party briefly accessed its online purchase and order platform and that limited personal information belonging to some customers was accessed.
What Oz Hair & Beauty has confirmed
Oz Hair & Beauty has published an official cyber incident statement saying it began a forensic investigation and containment work as soon as it became aware of the incident, with technical specialists from its cloud e-commerce platform provider.
The company says the incident has been contained, its website and app can be used as normal, and customers whose information was affected are being contacted directly. It has reported the incident to the Australian Cyber Security Centre, the Office of the Australian Information Commissioner and New Zealand’s Office of the Privacy Commissioner.
For affected customers who purchased before August 2026, the company says the information involved includes:
- full name;
- email address and/or mobile number;
- currency used;
- total spend;
- purchase location; and
- the date the customer record was created.
The company says the accessed information did not include credit card details, passwords, payment information or invoice details.
The second section of Oz Hair & Beauty’s official statement. Screenshot retained for reporting and commentary.
Oz Hair & Beauty says that if a customer does not receive an email by Saturday, 22 August 2026, its investigation has not identified that person’s information as affected to date. The words “to date” matter: incident investigations can develop, and the statement leaves room for the company to update its position if new evidence emerges.
What remains unconfirmed
The company’s statement does not give a total number of affected customers, describe the initial access method, identify how long the third party was present beyond calling the access brief, or say whether the accessed records were copied in bulk.
An earlier Recent Breaches report described a published file said to contain about two million email addresses together with names, phone numbers, suburb-level locations and purchase-related information. That is third-party reporting, not a number Oz Hair & Beauty has confirmed in its official statement.
The distinction is important. The company has now confirmed unauthorised access and named the categories of customer information involved. It has not publicly confirmed the reported dataset size or every field attributed to it elsewhere.
Why purchase data matters without a card number
It is reassuring that payment details and passwords were not involved, but it would be a mistake to conclude that the remaining information has little value.
A real name, phone number, shopping location and total spend can give a scammer enough context to make an email, text message or phone call sound believable. A fake refund, loyalty credit, delivery problem or account-verification message is harder to spot when it includes details that feel private and accurate.
The likely follow-on risk is therefore targeted phishing and social engineering, rather than someone immediately charging a card from this dataset. A scammer can use genuine details to establish trust, then ask the customer to click a link, disclose a one-time code or provide the sensitive information that was not present in the original record.
This is the same practical lesson that came out of the Nick Scali incident. Retail records do not need to contain financial credentials to support a convincing impersonation attempt.
From a receipt to a behavioural profile
This incident also raises a wider privacy question: what does a retailer learn from an ordinary transaction, and how long should it keep that information?
The ABC reported in 2024 on concerns about the consumer data collected through Coles’ Flybuys and Woolworths’ Everyday Rewards programs. Those schemes can collect what, how, when and where customers buy, then use that information for personalised marketing and insights into customer behaviour.
The situations are not identical. Oz Hair & Beauty has not said that item-by-item invoices or a detailed list of products were accessed here. Its statement names total spend, currency, purchase location and customer creation date. The connection is the value of transactional data itself. Records collected for fulfilment, marketing, rewards or forecasting can gradually become a profile of where somebody shops, how often they return and how much they spend.
That profile is useful to a retailer. In the wrong hands, even a partial version can also be useful to a criminal.
Oz Hair & Beauty says it is reviewing both its cyber security posture and its data retention policies. I am glad the company named retention specifically. Businesses cannot expose customer information they no longer hold, and reducing old or unnecessary records is one of the few security controls that removes the consequence rather than merely reducing the likelihood.
The customer support load is part of the incident
When I checked the Oz Hair & Beauty website, its automated help tool acknowledged a high influx of customer tickets, said customers should expect an update within 48 hours, and apologised that the delay was not satisfactory. It also linked customers back to the official statement and the company’s privacy email address.
The customer support message visible on the Oz Hair & Beauty website after the incident.
That operational pressure is worth noticing. A breach does not end when access is contained. For a customer-facing business, the response also means identifying affected records, sending notifications, answering legitimate questions and dealing with the phishing messages that may imitate those notifications.
What customers should do now
There is no reason in the company’s statement to cancel a payment card solely because of this incident. Oz Hair & Beauty says card and payment details were not involved.
There are still some sensible precautions:
- Treat unexpected Oz Hair & Beauty messages cautiously. Be especially wary of messages about refunds, rewards, deliveries or account verification.
- Do not sign in or provide details through a link in an email or text. Open the official website or app yourself, or contact the retailer using details sourced independently.
- Never give a password, payment detail or one-time security code to somebody who contacts you. Oz Hair & Beauty says its notification email will not ask for these.
- Use a unique password and multi-factor authentication where available. Passwords were not involved in this incident, but unique credentials stop an unrelated breach or phishing attempt spreading into other accounts.
- Continue checking financial statements as a normal precaution. Contact your bank immediately if an unfamiliar transaction appears, but do not assume this notice means your card number was exposed.
- Verify uncertain messages directly. The company lists
[email protected]for incident questions.
There is no indication in the company’s statement that the Willows store itself was breached. The Townsville connection is that local customers now recognise and deal with the same brand in person and online. That familiarity is precisely what makes later impersonation attempts effective.
For businesses, the question is not only whether customer data is encrypted or access-controlled. It is whether every retained field still serves a real purpose, who can export it, how activity on the platform is monitored, and when old records are deleted.
A transaction may be finished in minutes. The data around it can remain valuable, and risky, for years.
