Your Data May Already Be Out There. The Hollywood Fancy Dress Breach Exposed 13,846 Customer Records.
In October 2024, Hollywood Fancy Dress, a UK-based e-commerce retailer specializing in costumes and accessories, suffered a database breach that exposed the personal details of nearly 14,000 customers. The leaked records included names, email addresses, and phone numbers, giving attackers everything they need to run convincing impersonation scams. Smaller retailers often hold the same volume and sensitivity of customer data as major brands but without the same security resources, making breaches like this one a persistent problem across the e-commerce sector.
Why This Is Dangerous
Phone numbers are the detail that elevates this breach above a standard email list leak. With a name, email, and phone number together, attackers can bypass two-factor authentication (2FA) by using the phone number to intercept SMS codes through SIM swapping or social engineering attacks on mobile carriers. This combination also makes highly targeted voice phishing (vishing) attacks possible, where a caller impersonates a bank, delivery service, or even Hollywood Fancy Dress itself to extract additional information or payments.
What Was Exposed
- Email addresses -- used for phishing and account access attempts
- Phone numbers -- enables SMS phishing, vishing, and SIM swap attacks
- First and last names -- make targeted communications convincing
Records exposed: 13,846 | Breach type: Database | Date leaked: October 2024 | Country: United Kingdom
Why This Matters
- SMS phishing (smishing): Attackers text victims posing as delivery companies or the retailer with malicious links to steal payment details.
- Voice phishing (vishing): Criminals call victims by name, referencing their purchase history, to sound legitimate while extracting banking credentials.
- SIM swapping: Phone numbers can be used to take over accounts protected by SMS-based 2FA, including email, banking, and social media accounts.
- Account takeover: Email plus name plus phone number is sufficient for many account recovery processes.
- Identity theft: The combination of contact identifiers is enough to open fraudulent accounts or pass customer verification checks.
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to the data store behind a website or application. For e-commerce sites, common attack vectors include SQL injection flaws in the checkout or account management pages, compromised admin credentials, insecure third-party plugins, and unpatched content management system vulnerabilities. After exfiltration, the stolen data typically appears on dark web marketplaces or underground forums within days, where it is purchased by criminals running phishing, fraud, and account takeover operations.
Check If You Are Affected
Heroic's database holds over 400 billion breached records collected from thousands of known data leaks. Search your email address for free to find out whether you appear in the Hollywood Fancy Dress breach or any other incident in our database.
Search your email now at Heroic.com -- free, instant, and private.
Breach Breakdown
13,846 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds