The Ozon Marketplace Breach Gave Attackers Phone Numbers and Names to Target Shoppers
In December 2024, customer data from Ozon Marketplace, one of Russia's largest and most established e-commerce platforms, appeared on underground data forums. Our analysts documented 429 records containing phone numbers and full names. While the record count is modest, Ozon's massive user base means this breach represents a real and specific threat to the individuals whose data was exposed. Attackers armed with verified phone numbers and real names tied to an active shopping account have everything they need to launch convincing fraud campaigns.
What the Ozon Marketplace Breach Handed Attackers
A name and phone number pulled from a known e-commerce platform is a powerful fraud toolkit. Attackers can call or text victims while impersonating Ozon customer service, referencing their real account to make the contact appear legitimate. This technique, known as vishing (voice phishing) or smishing (SMS phishing), is used to steal login credentials, payment details, or one-time verification codes. The legitimacy that comes from knowing the target's real name and their connection to the platform makes these attacks significantly more convincing than cold-contact fraud.
What Was Exposed
- First name
- Last name
- Phone number
Why This Matters
Phone numbers and names are the foundation of social engineering attacks. When this data is combined with information from other breaches, attackers can build complete victim profiles used for account takeover, identity theft, and financial fraud. E-commerce platforms are high-value targets because their customers have active payment methods linked to their accounts. A single successful social engineering call can result in unauthorized purchases, stolen payment credentials, or full account hijacking.
How E-Commerce Database Breaches Happen
Database breaches at online retailers typically occur through vulnerabilities in web applications, insecure API endpoints, or compromised employee credentials with database access. In some cases, misconfigured cloud storage exposes customer records without any authentication required. Once an attacker copies the database, the records are sold on private forums or dark web marketplaces, where other criminals purchase them to fuel fraud and phishing campaigns. Large platforms like Ozon are frequent targets because the data is directly linked to active shoppers with payment methods on file.
Check If You Are Affected
HEROIC's identity protection platform monitors more than 400 billion exposed records from data breaches worldwide. If your phone number or email appeared in the Ozon Marketplace breach or any related leak, you will receive an alert so you can take protective action before attackers reach you. Run a free scan at HEROIC.com and find out whether your personal data is already in circulation.
Breach Breakdown
429 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds