[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1lwiwbr3vsyux":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":33,"seoTitle":34,"seoTitleEn":35,"seoDescription":34,"seoDescriptionEn":36,"logoUrl":37,"isVerified":4,"isSensitive":4,"isSpamList":38,"isMalware":38,"company":39},"68e3266eda11adda4882511e","bonobos","Bonobos Data Breach","bonobos.com","2020-08-14T00:00:00.000Z","2021-01-31T00:09:25.000Z","2026-07-09T16:54:11.043Z","2026-07-18T23:46:28.689Z","Third party breach","https:\u002F\u002Fwww.clearycyberwatch.com\u002F2022\u002F01\u002Fdata-breach-class-action-against-bonobos-dismissed-for-lack-of-standing\u002F",[15,17],"https:\u002F\u002Fdatabreach.com\u002Fbreach\u002Fbonobos.com-2020",2811929,"known",null,"unknown","Critical",[24,25,26,27,28,29,30,31,32],"Email addresses","Historical passwords","IP addresses","Names","Partial credit card data","Passwords","Phone numbers","Physical addresses","Purchases","\u003Cp>The Bonobos data breach is related to the exposure of customer and account records on the men's clothing retailer bonobos.com. The incident was recorded on August 14, 2020, and the confirmed impact is at the level of 2,811,929 unique email addresses. The inclusion of account, order, contact, and partial payment card fields together in approximately 70 GB of customer data makes this breach significant not only in terms of password security but also in terms of phishing and fraud risk.\u003C\u002Fp>\n\u003Cp>The critical aspect of the breach is that the retail account information is combined with shopping history and partial card details. The verified data classes include email addresses, names, phone numbers, physical addresses, IP addresses, purchase information, partial credit card data, current passwords, and past passwords. Passwords were reported to be stored as salted SHA-512 hashes; while this structure is stronger than plain text passwords, if passwords are reused, it can still pose a risk to users' other accounts.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The fields verified in the Bonobos record are quite extensive: email addresses, names, IP addresses, phone numbers, physical addresses, purchase history, partial credit card information, passwords, and past passwords. Partial card data may include payment details such as card type, name on the card, expiration date, and the last four digits. These fields do not replace the full card number; however, they can be used to make phishing messages more convincing.\u003C\u002Fp>\n\u003Cp>When purchase history and address information are found together, it becomes easier to generate fake shipping, return, invoice, campaign, or account verification messages tailored to the user. Having password hashes as salted SHA-512 provides an important layer of protection; however, the risk persists when old or reused passwords are compared with other data sets. Including past passwords is also important, as it can reveal patterns of passwords previously used by the user.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified scope for this record is 2,811,929 unique email addresses. The data classes in the record are email addresses, past passwords, IP addresses, names, partial credit card data, passwords, phone numbers, physical addresses, and purchase information. Full credit card numbers, card security codes, or bank account information are not among the verified fields for this record. This distinction should be maintained both to avoid understating the risk and to avoid overstating it by including unverified fields.\u003C\u002Fp>\n\u003Cp>The incident concerns Bonobos customer data and automatic additional breach assumptions should not be made for different retail brands within the same company family. The number in the record reflects the effect of unique email addresses; order lines, card records, or address records may produce different numbers. The main impact shown to the user should be evaluated based on the number of verified unique accounts and the listed data classes.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The most at-risk group consists of customers who have a Bonobos account, have shopped in the past, and have used the same password on other e-commerce or email accounts. Users with address, phone number, and order history can be targeted with fake delivery, return, payment update, or customer service messages. Partial card information can provide attackers with details that strengthen the impression that the user is indeed a Bonobos customer.\u003C\u002Fp>\n\u003Cp>Due to past password fields, not only the password at the time of the breach but also previously used password patterns should be considered risky. If a user believes that their old password has continued in other accounts with minor changes, they should prioritize updating those accounts. In particular, email accounts, shopping sites, payment services, shipping accounts, and social media accounts can be directly affected by such data combinations.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>Users who see a match in this record should first change their password on their Bonobos account and any other accounts where the same password may have been used. With a password manager, unique, long, and hard-to-guess passwords should be created for each account. Since past passwords may also have been exposed, one should not revert to old password patterns or use similar variations. Email accounts and payment-related accounts should be protected as a priority.\u003C\u002Fp>\n\u003Cp>Users should be cautious about fake shipping notifications, return forms, payment verification, card updates, or special discount messages. Instead of logging in through incoming links, the relevant service should be accessed directly, unexpected attachments should not be opened, and card transactions should be monitored regularly. If the bank or card provider offers unusual transaction alerts, these alerts should be enabled. Using two-factor authentication on critical accounts provides additional protection.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The Bonobos incident shows that e-commerce accounts carry not only shopping convenience but also a strong personal data profile. Users should regularly review the addresses, payment-related records, and past order information stored in their retail accounts. Accounts that are no longer in use should be closed, registered payment methods should be removed if possible, and delivery addresses should be limited to current needs. Using the same email address across all shopping sites can also increase the risk of targeted phishing.\u003C\u002Fp>\n\u003Cp>From a corporate security perspective, retail data requires the protection of backup management, access control, password storage, payment data segmentation, and incident reporting processes together. On the user side, unique passwords, multi-factor authentication, card activity tracking, and regular account cleaning should be implemented together. Even if password hashes are strong, the combination of communication and purchase data keeps the social engineering risk alive for a long time.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>The presence of a match with the email address in this record indicates that the user is included in the Bonobos data set. The user should first assess which password was used on the Bonobos account, on which accounts this password has been reused before, and which personal information is recorded on the shopping account. Then, passwords should be renewed, especially for email, payment, shopping, and shipping-related accounts.\u003C\u002Fp>\n\u003Cp>A match does not prove that the full card number has been exposed; however, the presence of partial card information, address, phone number, purchase history, and password hashes together is a serious warning. Users need to make their passwords unique, use two-factor authentication, monitor card activity, and check messages directly through a trusted channel. These steps significantly reduce the risks of account takeover, targeted fraud, and phishing that could arise from the Bonobos breach.\u003C\u002Fp>","","Bonobos Data Breach (2.8 Million Reported Records)","Bonobos Data Breach. 2.8 Million reported records were reported. Reported data: Email addresses, Historical passwords, IP addresses. Review the scope, risks…","\u002Fuploads\u002Flogo\u002Fbonobos_com.webp",false,{"name":40,"sector":41,"country":42,"website":9,"websiteArchiveUrl":34,"websiteStatus":34,"websiteCheckedAt":20},"Bonobos","Retail \u002F apparel e-commerce","United States"]