Fragrance Shoppers Exposed: Parfum Duty Free Breach Leaked 9,770 Records
HEROIC analysts identified a database breach affecting Parfum Duty Free, a now-defunct U.S.-based online shopping retailer specializing in perfumes and fragrance products. The breach surfaced on July 25, 2024, and exposed 9,770 customer records containing email addresses, phone numbers, first names, and last names. No passwords were included in the leaked dataset.
Why This Is Dangerous
With full names, email addresses, and phone numbers in hand, attackers can build convincing impersonation campaigns. Because Parfum Duty Free is no longer operating, affected customers cannot receive a notification from the company, and there is no ongoing customer support channel to report concerns to. This makes victims particularly vulnerable, as they are unlikely to be warned directly and may not realize their data was ever compromised. Criminals can use this contact information for targeted phishing, smishing, or social engineering attacks that impersonate other familiar brands.
What Was Exposed
- Email Address
- Phone Number
- First Name
- Last Name
Why This Matters
Data from defunct retailers is particularly persistent as a risk because no remediation is possible at the source. The names and contact details in this dataset can fuel credential stuffing attempts against other services using the same email address, account takeover schemes executed through social engineering, identity theft applications, and spam and fraud campaigns. Personal data does not expire once it is on an underground forum, and small shopping site breaches are frequently bundled with larger datasets to create more complete victim profiles.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to a structured data store and extracts records it contains. Common attack paths include SQL injection vulnerabilities in web-facing applications, compromised administrative credentials, misconfigured database permissions that expose data to the internet, or exploitation of unpatched database software. Once inside, an attacker can dump entire tables of customer records in minutes. The extracted data is then typically sold or published on underground forums, putting affected individuals at risk long after the initial intrusion and, in this case, long after the business has closed.
Check If You Are Affected
If you ever shopped at Parfum Duty Free or parfum-duty-free.co, your contact details may be in this dataset. Use the HEROIC free identity scanner to search your email address across more than 400 billion exposed records and find out whether your personal data has been compromised in this or any other known breach.
Breach Breakdown
9,770 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds