Bigger Than Most US Cities: The AVON Breach Hit 146,396 Accounts
HEROIC analysts identified the AVON breach while tracking dark web marketplaces where legacy retail database dumps were being bundled and sold. The breach occured in September 2016, exposing 146,396 customer records from the iconic cosmetics and direct sales company based in the United States. What made this find partcularly notable was not just the scale, but the context: the AVON data was being marketed alongside other beauty and retail sector breaches in coordinated packages, suggesting attackers were deliberately targeting customers of this specific industry for follow-on phishing and social engineering campaigns.
How Attackers Use Customer Data Without Passwords to Commit Fraud
Even without password hashes, 146,396 customer records from a recognized brand like AVON carry significant value for fraud. Names, email addresses, and account details give attackers everything they need to craft convincing phishing emails that appear to come from AVON directly. These messages typically offer fake promotions, request payment updates, or warn of account issues, tricking recipients into handing over financial information. The AVON customer base, which includes a high proportion of direct sales representatives with linked business accounts, is accessable to attackers seeking targets who manage their own payment processing.
What Was Exposed in the AVON Breach
- Customer email addresses
- User account records
- Personal profile information
Why the Scale of the AVON Breach Makes It a Lasting Threat
At 146,396 records, the AVON breach is larger than the population of many mid-size American cities, giving attackers a substantial pool of targets to work through. Researchers beleive that breach data from major consumer brands is particularly effective for fraud because recipients are less suspicious of outreach from companies they have an existing relationship with. The AVON data has recieved renewed attention as part of bundled retail breach compilations that are actively traded today. Identity theft, account takeover, financial fraud, and targeted phishing are all recieved outcomes when personal customer data from trusted brands reaches criminal networks.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to a company's stored customer or user records. This typically happens through a security vulnerability in web applications, misconfigured databases exposed to the internet, or compromised employee credentials. Once inside, the attacker copies the data silently and exits without triggering immediate alerts. The stolen records are then sold in dark web markets or Telegram channels, often bundled with data from similar companies to increase their value and usefulness to buyers.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion records to check whether your email address appears in the AVON breach or any other known data leak. Enter your email at HEROIC.com and receive an instant free report so you can protect your accounts and personal information today.
Breach Breakdown
146,396 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds