LuLu Hypermarket Shoppers Hit by UAE Retail Data Breach
HEROIC analysts found a database breach exposing 190,512 records belonging to customers of LuLu Hypermarket, the prominent UAE-based retail chain. Discovered on July 6, 2024, the initial exposure placed email addresses and phone numbers on a well-known hacking forum. The breach escalated the following month when the full database — a backup from October 2022 — was leaked, expanding the scope to 2.6 million unique email addresses along with names, physical addresses, order details, and PBKDF2 password hashes.
Why This Is Dangerous
This breach combines personal identifiers, contact details, and hashed credentials in a single dataset. Attackers with access to email addresses, phone numbers, full names, and physical addresses can launch targeted phishing campaigns, SIM-swap attacks, and social engineering attempts against affected shoppers. The inclusion of PBKDF2 password hashes means that, given sufficient compute resources, some passwords can be recovered and tested against other services where users have reused credentials.
What Was Exposed
- Email Address
- Phone Number
- First Name
- Last Name
- Password Hash
Why This Matters
When full name, email address, phone number, and password hash data are combined in a single leak, the risk compounds significantly. Credential stuffing attacks become viable for any other service where the affected user shares that email and password combination. Account takeover can cascade across banking, e-commerce, and social platforms. Physical addresses in the dataset open the door to identity theft, fraud, and targeted mail-based scams directed at LuLu shoppers across the United Arab Emirates and the wider Gulf region.
How Database Breaches Work
A database breach occurs when an unauthorized party gains access to a backend data store — typically through vulnerabilities such as SQL injection, misconfigured cloud storage, compromised administrative credentials, or unpatched server software. Once inside, attackers export structured records containing user data. In this case, a backup file from October 2022 was included in the leak, suggesting that historical backup archives were either inadequately secured or stored in a location accessible to the attacker. Backup files are a frequent target precisely because they often fall outside the same security controls applied to live production databases.
Check If You Are Affected
HEROIC offers a free dark web scanner that checks your email address against more than 400 billion compromised records, including breach data of this type. If you shopped at LuLu Hypermarket and provided your email address, you should run a scan immediately, change your LuLu account password, enable two-factor authentication where available, and remain alert to phishing emails or unexpected calls referencing your LuLu purchase history.
Breach Breakdown
190,512 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds