Inside the Joyalukkas Database Breach: 980 Customer Records Stolen
In October 2024, the UAE-based eCommerce jewelry retailer Joyalukkas suffered a database breach that exposed 980 customer records. The compromised data included email addresses, phone numbers, and full names — a combination that creates real risk for the people affected. If you shopped on eshop.joyalukkas.com, your personal information may now be in the hands of threat actors.
Why This Is Dangerous
Database breaches targeting eCommerce platforms are among the most actionable leaks for cybercriminals. When attackers obtain a customer's name, email address, and phone number together, they have everything they need to launch convincing phishing emails and SMS scams that appear to come from a trusted retailer. Even without passwords, this data is immediately useful for social engineering and identity verification bypass.
What Was Exposed
- Email addresses — used for phishing and credential stuffing across other services
- Phone numbers — used for SMS phishing (smishing) and SIM-swap attacks
- First and last names — used to personalize fraudulent communications and bypass identity checks
Why This Matters
Even a breach of 980 records can have outsized consequences. Attackers use leaked customer lists to:
- Craft targeted phishing emails that reference your real name and purchase history
- Attempt account takeovers on Joyalukkas and other platforms where you reuse credentials
- Commit identity theft by combining your data with other leaked records
- Execute financial fraud by using your contact details to impersonate you with banks or service providers
How a Database Breach Works
A database breach occurs when an attacker gains unauthorized access to a backend database — the system that stores customer records behind an eCommerce website. Common attack vectors include SQL injection (manipulating database queries through vulnerable input fields), exposed database credentials, and misconfigured cloud storage. Once inside, attackers can export entire tables of customer data in minutes. In the Joyalukkas case, the structured format of the leaked data points to a direct database table dump rather than a surface-level web scrape.
Check If You Are Affected
HEROIC's dark web monitoring database contains over 400 billion exposed records. If your email address or personal information appeared in the Joyalukkas breach or thousands of other leaks, you can find out instantly. Search the HEROIC database now to see if your data has been compromised and take steps to protect yourself before attackers act.
Breach Breakdown
980 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds