[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f38c3dlahpa8p3":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":22,"affectedCountUnit":23,"hasEnglishDescription":4,"severity":24,"dataClasses":25,"description":32,"seoTitle":33,"seoTitleEn":34,"seoDescription":33,"seoDescriptionEn":35,"logoUrl":36,"isVerified":4,"isSensitive":37,"isSpamList":37,"isMalware":37,"company":38},"68e3266eda11adda488251a5","dymocks","Dymocks Data Breach","dymocks.com.au","2023-06-20T00:00:00.000Z","2023-09-08T07:35:22.000Z","2023-09-08T07:46:30.000Z","2026-07-18T23:50:09.628Z","Third party partner breach","https:\u002F\u002Fwww.dymocks.com.au\u002Fcustomer-notices",[15,17,18,19],"https:\u002F\u002Fwww.abc.net.au\u002Fnews\u002F2023-09-15\u002Fdymocks-confirms-1-million-customers-details-leaked\u002F102863820","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fdymocks-booksellers-suffers-data-breach-impacting-836k-customers\u002F","https:\u002F\u002Fia.acs.org.au\u002Farticle\u002F2023\u002F1-2-million-customers-caught-up-in-dymocks-breach.html",836120,"known",null,"unknown","High",[26,27,28,29,30,31],"Dates of birth","Email addresses","Genders","Names","Phone numbers","Physical addresses","\u003Cp>The Dymocks data breach is a personal data leak affecting the customer records of the Australia-based bookstore and is dated to June 2023. The breach is recorded as occurring on 20 June 2023 in terms of the record system; the incident was announced to customers in September 2023. The dataset contains approximately 1.24 million customer contact records and 836,120 unique email addresses. This distinction is important: the total number of records is not the same as the number of unique individuals or unique emails.\u003C\u002Fp>\n\u003Cp>The verified data classes are birth dates, email addresses, gender information, full names, phone numbers, and physical addresses. Company statements indicate that passwords, payment cards, identity documents, or financial transaction information are not included in this incident. Nevertheless, since fields that do not change for a long time, such as birth date, phone number, and address, have been leaked, the risk should not be considered low. This information can make fake shipments, fake purchases, account updates, and customer service messages more convincing.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>Having an email address, phone number, full name, and physical address together in a Dymocks record makes it easier to reach the user directly. In the context of book retail, this gives attackers the opportunity to create fake order, promotion, shipping, return, or membership update scenarios. If date of birth and gender information are also included, messages may appear more personal and weak verification questions used in some account recovery processes could become predictable.\u003C\u002Fp>\n\u003Cp>This breach should not be presented as a direct card fraud or password cracking incident because no password or payment card was verified. However, profile and contact data alone also pose a serious social engineering risk. The combination of physical address, phone, and email can be used in messages targeting the user with excuses such as home delivery, membership points, book orders, or shipping fees. Therefore, a Dymocks record should be considered a persistent personal data risk, even if it does not include financial data.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified main impact count for this record is 836,120 unique email addresses. The total customer contact record has been reported as approximately 1.24 million. It is understood that the dataset extends until June 2023, the company noticed the incident in September 2023, and it has been confirmed that customer records circulated in dark web environments. Therefore, the date of the incident and the date of public announcement should be kept separate.\u003C\u002Fp>\n\u003Cp>Verified data categories are date of birth, email, gender, name, phone, and physical address. Some customer notifications mention retail membership details such as membership status or membership card ranking; however, in this record, the main data categories should be maintained as personal contact and demographic fields. Passwords, payment cards, passports, driver’s licenses, identification numbers, or transaction history should not be included in the verified scope of this record. This boundary provides an accurate risk description without causing unnecessary panic to the user.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>In the highest risk group are those who have a Dymocks customer account and have shared their real phone number and address for book orders, loyalty membership, or store communication. These users may be targeted with fake book campaigns, delivery fees, return confirmation, membership points, or account update messages. Users with birth date information should be more cautious of phishing messages themed around birthday discounts or membership benefits.\u003C\u002Fp>\n\u003Cp>Customers in Australia and surrounding markets can be targeted in the local store, shipping, and loyalty program language. The risk for individuals who use the same email address in other retail accounts is the linking of different shopping accounts. Users registered with a corporate email address can also be targeted with fake invoices, event invitations, or corporate purchase messages. Since hard-to-change data such as address and phone number has been leaked, the risk is not limited to the period when the incident was announced.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>If your email address appears in the Dymocks registry, carefully review any messages in your inbox about book orders, shipping, membership points, returns, or account verification. Instead of clicking the link in the message, access your account directly from a browser or the official app. Even though a password leak has not been confirmed for this registry, if you have weak or reused passwords during the same period, it is a good precaution to update passwords for your important shopping and email accounts.\u003C\u002Fp>\n\u003Cp>Be careful with requests received via text message, call, and mail, as your phone number and physical address may have been leaked. Do not process messages requesting payment under the pretext of shipping fees, delivery confirmation, gift cards, or membership points without verification. Check for unknown sessions and forwarding rules in your email account. If other retail accounts registered with the same email address have two-factor authentication, enable it.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The Dymocks incident shows that retail companies need to regularly review how long they keep long-lasting personal data such as birth date, gender, and address and for what purpose. Institutions should reduce unnecessary data collection, limit old or inactive customer records with retention policies, and regularly audit third-party data partners. The absence of passwords in personal data does not eliminate the need for data minimization and access control.\u003C\u002Fp>\n\u003Cp>The long-term approach on the user side is to avoid filling in unnecessary profile fields in retail accounts and to separate email addresses according to their purposes. Permanent information such as physical addresses and phone numbers cannot be recovered if leaked; therefore, it is important not to share these fields in unreliable campaign and membership forms. Corporate users should avoid opening personal retail accounts with their business emails and should also evaluate incoming shopping and shipping messages in terms of phishing risk.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>If your email address appears in this record, do not conclude that your password or payment card has been leaked; these fields are not within the verified scope. However, your name, email address, phone number, address, date of birth, and gender information may be found together. This combination is sufficient to personalize fraud messages. Avoid suspicious links, check your Dymocks account directly, and verify unexpected contact requests through official channels.\u003C\u002Fp>\n\u003Cp>The right action is to focus on preventing the misuse of personal communication data. Check your email security, be cautious of suspicious messages received on other retail accounts with the same contact information, and do not accept payment or verification requests over the phone. The Dymocks data breach shows that leaks, even if they do not contain financial data but include permanent fields such as date of birth, phone number, and address, can pose long-term social engineering risks.\u003C\u002Fp>","","Dymocks Data Breach (836.1 Thousand Reported Records)","Dymocks Data Breach. 836.1 Thousand reported records were reported. Reported data: Dates of birth, Email addresses, Genders. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fdymocks_com_au.webp",false,{"name":39,"sector":40,"country":41,"website":9,"websiteArchiveUrl":33,"websiteStatus":33,"websiteCheckedAt":22},"Dymocks","Retail","Australia"]