Lookiero Data Breach: 4.98M Customer Records Exposed
5 Million Lookiero Customers' Personal Data Exposed in Fashion Site Breach
Online personal styling service Lookiero suffered a data breach affecting approximately 4.99 million customers. The compromised data -- including email addresses, full names, phone numbers, and physical addresses -- appeared on a popular hacking forum in August 2024, though the breach itself dates to March 2024. The incident is notable for what it doesn't include (passwords) as well as what it does: detailed personal contact information for millions of UK shoppers who trusted Lookiero with their details.
Lookiero Data Breach: Breach Summary
- Records Exposed: 4,985,787
- Data Types: Email addresses, first names, last names, phone numbers
- Breach Type: Database breach
- Country Affected: United Kingdom
- Date Leaked: March 2024 (publicly disclosed August 2024)
Why PII Breaches Without Passwords Still Matter
When a breach exposes personal data but no passwords, it's tempting to treat it as a lesser threat. That assessment is wrong. A dataset containing someone's email address, full name, phone number, and home address is exactly what social engineers need to execute convincing phishing and vishing (voice phishing) attacks. A threat actor with this informaton can call a Lookiero customer by name, reference their account, and persuade them to hand over their password voluntarily. They can craft personalised emails that appear far more credible than generic phishing messages. The absence of passwords in the breach itself doesn't prevent attackers from obtaining them through follow-on manipulation.
Lookiero's Response and What Customers Should Know
When contacted about the breach, Lookiero reportedly said they would "look into it and get back to you if necesary." That response fell substancialy short of the transparent, timely breach notification that affected customers deserved. For anyone who used Lookiero, the immediate steps are: watch for unusually targeted phishing emails or phone calls referencing your Lookiero account, be cautious about any communication claiming to be from Lookiero or related services, and check whether your email address has appeared in other known breaches.
Check if Your Email Was in the Lookiero Breach
HEROIC's free breach scanner searches across more than 400 billion exposed records, including database breaches like the Lookiero incident. Enter your email to see if your personal information has been exposed in this or any other known breach. Even without passwords in the breach itself, having your contact details in criminal hands is a risk worth knowing about so you can stay alert to follow-on attacks.
Breach Breakdown
4,985,787 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds