Image via Augustine Bin Jumat/Shutterstock

According to a leading cybersecurity firm, more than three million records of customers of international cosmetics and beauty products retailer Sephora are reportedly up for sale on the Dark Web.
Singapore-based cybersecurity outfit Group-IB said in a media release on Thursday (1 Aug) that its cyber intelligence analysts located “two databases with customer data on underground forums that are likely to be related to Sephora”.
These databases are believed to contain records from February and March this year, which corresponds with the recent Sephora data breach that affected the personal data of its online customers in Singapore, Malaysia, Indonesia, Thailand, the Philippines, Hong Kong, New Zealand, and Australia.
CEO and founder of Group-IB Ilya Sachkov said in the media release that the first database was advertised on two Dark Web forums on 16 and 17 July, respectively.
According to the seller, the database “consists of 500,000 records including the usernames and hashed passwords from Sephora.co.id (Indonesia) and Sephora.co.th (Thailand)”.
“The listing’s author notes that the data comes from February 2019,” he added.
Meanwhile, the second database surfaced on an underground forum on 28 July, a day before the news of the breach was made known by Sephora.
“As its name implies “Sephora 2019/03 – Shopping – [3.2 million]”, the database contains 3.2 million records, and was leaked in March 2019,” said Mr Sachkov.
With its high-tech tools, Group-IB’s cyber intelligence team “infiltrated sources in closed hacking communities” and initiated contact with the seller, who then supplied the sample of the data being sold.
Mr Sachkov noted that the sample revealed that the database contains all sorts of personal data such as login, encrypted password, date of registration and last activity, IP of registration, last IP, gender, name, surname, ethnicity, eye color, skin tone, skin type, hair color, hair concerns, makeup essentials, and skincare routines.
He then pointed out that the set of data was priced at USD 1,900 (S$2,613).
Even though the records do not include any payment information or decrypted passwords, such detailed information about the customers can be used to carry out social engineering or targeted phishing attacks that is why the scale of the breach shouldn’t be underestimated,” he stated.
“As a precaution, we advise all customers who had accounts at Sephora to change their password, especially if they use the same login/password pair across multiple services, such as email and social media accounts, to avoid them being compromised,” he added.
TOC has reached out to Sephora earlier today for its comments on Group-IB’s findings. We have yet to receive a response, but will provide an update upon receiving a reply.

Subscribe
Notify of
0 Comments
Inline Feedbacks
View all comments
You May Also Like

Lawyer M Ravi files case in High Court on behalf of husband seeking to use his CPF savings to fund his cancer-stricken wife’s medical treatment

International human rights lawyer M Ravi took to his Facebook page on…

【选举】IHH收购印度医疗机构受阻 惟前总裁陈诗龙荣休今年参选

人民行动党上周在线上介绍了27名新面孔,其中一人是55岁的IHH医疗保健集团管理层的前总裁兼董事经理,陈诗龙医生。令人感到疑惑的是,在他离职时,IHH正面对收购印度医疗机构富通的交易纠纷,而他似乎没选择留下来提供协助。 陈诗龙于2014年1月至2019年12月在IHH任职。然而在他去年合约结束,选择退休。 IHH医疗保健集团在我国、马来西亚、中国、土耳其和印度都有业务,也是我国和马来西亚的上市公司。其旗下的百汇班台(Parkway Pantai Ltd)更是集团的御宝,在亚洲拥有医院网络,包括我国的伊丽莎白医院、伊丽莎白诺维娜医院、鹰阁医院和百汇东岸医院。 行动党委派陈诗龙医生出战马林百列集选区,直接对垒工人党。 IHH在印度收购富通受阻 IHH医疗保健公司在2018年7月,成功赢得收购印度第二大医院经营机构-富通保健股权的竞标战,并于同年11月通过优先配股购买31.1巴仙股权,还打算随后收购额外的26巴仙股权。但是日本制药公司第一三共株式会社(Daiichi Sankyo)和富通保健的创办人辛格兄弟对簿公堂,因此印度最高法院下令IHH暂缓收购交易。辛格兄弟当时也接受印度当局的欺诈调查。 在2019年11月15日,印度法院裁定富通保健前持有人,辛格兄弟和富通藐视法庭罪名成立,也表示或对当时已经由IHH掌控的富通公司展开藐视法庭审讯。这是因为法院指IHH和富通的部分交易,被视为违反了2018年12月的庭令。 法院当时曾对双方部分交易展开调查,甚至调查富通董事会和管理层的详情,发现相关交易都是非常仓促和秘密在进行,进而违反了2018年所发出的庭令。 印度当局下令调查富通…

Josephine Teo concurs raising dormitory standards is important, but MOM will first focus containing COVID-19 transmission

Manpower Minister Josephine Teo concurred that raising the standards in foreign worker…

SPH's profits down again – it's share price has dropped 30% since Ng came onboard

After the close of the markets last Friday (12 July), it was…