8,901 Revolution Beauty Customer Records Leaked on the Dark Web
In February 2022, a database containing customer records from Revolution Beauty, a UK-based makeup and skincare retailer, was found circulating on dark web forums. The breach recieved limited public attention despite exposing 8,901 customer records packed with personal identifiers including full names, email addresses, phone numbers, and birthdates, giving threat actors everything they need to impersonate or target affected customers.
What Attackers Can Do With Revolution Beauty Customer Data
With no passwords involved, this breach is entirely about identity data. Attackers armed with full names, birthdates, email addresses, and phone numbers can craft highly convincing phishing emails, attempt account recovery attacks on other platforms using birthday-based security questions, and build detailed profiles for SIM-swapping fraud. The combination of personal identifiers makes each affected customer seperate from a generic data point and instead a fully developed target profile ready for exploitation.
What Was Exposed in the Revolution Beauty Breach
- Email Address
- Phone Number
- First Name
- Last Name
- Birthday
Why PII-Only Breaches Are Underestimated Threats
Many consumers assume that if no passwords were leaked, the risk is minimal. The Revolution Beauty breach illustrates why this thinking is dangerous. Birthdates and phone numbers are commonly used for identity verification, account recovery, and two-factor authentication bypass. Combined with an email address and full name, the 8,901 exposed records create a ready-made toolkit for identity fraud, targeted scam calls, and social engineering attacks against Revolution Beauty customers across the United Kingdom.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to a company's stored customer data, typically by exploiting application vulnerabilities, weak access controls, or misconfigured cloud environments. In cases like the Revolution Beauty incident, the attacker exports customer tables directly from the backend database and posts the structured data on underground forums where it is traded, sold, or used for further attacks. The structured format of leaked PII makes it trivially easy to import into automated attack tools.
Check If Your Data Was Exposed
HEROIC's dark web monitoring database contains over 400 billion compromised records, including data from breaches like Revolution Beauty. Search now to find out if your email address or personal information was included in this leak, and take steps to secure your accounts and watch for suspicious activity targeting your identity.
Breach Breakdown
8,901 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds