[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1bwh0tm3tc5x3":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":33,"seoTitle":34,"seoTitleEn":35,"seoDescription":34,"seoDescriptionEn":36,"logoUrl":37,"isVerified":4,"isSensitive":38,"isSpamList":38,"isMalware":38,"company":39},"68e3266eda11adda488251da","white-room","Fashion Nexus Data Breach","fashion-nexus","fashionnexus.co.uk","2018-07-09T00:00:00.000Z","2018-07-31T08:20:54.000Z","2026-07-29T11:40:53.262Z","Third party breach","https:\u002F\u002Fwww.grahamcluley.com\u002Fonline-fashion-shoppers-exposed-ecommerce-breach\u002F",[15],1279263,"known",null,"unknown","Critical",[23,24,25,26,27,28,29,30,31,32],"Browser user agent details","Dates of birth","Email addresses","Genders","IP addresses","Names","Passwords","Phone numbers","Physical addresses","Purchases","\u003Cp>In July 2018, customer records of fashion e-commerce sites affected by the UK-based Fashion Nexus and associated White Room Solutions systems were circulated in unauthorized environments. The incident is significant because it touched a much wider retail network than a single store account: individuals who created accounts, placed orders, or shared delivery information through Jaded London, AX Paris, and other shopping sites connected to the same technical service group may be within the scope of this record. The verified scope includes 1,279,263 unique email accounts; it has been reported that the raw record count reached approximately 1.4 million rows. This discrepancy may be due to some individuals appearing in the system with multiple orders, addresses, or site registrations.\u003C\u002Fp>\u003Cp>The Fashion Nexus data breach should be taken into account especially for users with a history of fashion and clothing shopping. The leaked data is not limited to email addresses; it combines multiple identity and account security elements such as name, phone, physical address, purchase information, IP address, browser user-agent value, date of birth, gender, and password data. It has been reported that some of the passwords are stored in salted MD5, some in SHA-1, and some in unsalted MD5 format. Therefore, the incident should be considered high-risk both in terms of account takeover attempts and targeted fraud attempts fueled by delivery and order information.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>Among the verified data types in this record are email addresses, full name information, phone numbers, physical addresses, purchase histories, dates of birth, gender information, IP addresses, browser user-agent information, and password data. This combination of data poses risks beyond attackers merely sending generic phishing messages. If a person shopped at a fashion store during certain periods, used a particular delivery address, or shared certain contact information, this information could be convincingly misused in scenarios such as fake returns, delivery updates, promotions, shipping fees, account verification, or order cancellations.\u003C\u002Fp>\u003Cp>Having the password data in hash form does not mean that the plaintext password is immediately visible to everyone; however, MD5 and SHA-1 are considered weak according to current security expectations. Unsalted MD5 values are particularly risky because they can be compared relatively quickly with previously prepared password lists. Salting MD5 and SHA-1 values makes an attack more difficult, but the risk continues for short, reused, or dictionary-based passwords. Therefore, if the password used at Fashion Nexus or associated stores has been used on other sites, the same password should be changed on all accounts.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The number of verified unique accounts is 1,279,263 email addresses. The incident date is recorded as July 9, 2018, and the scope includes multiple e-commerce sites developed by White Room Solutions in connection with the retail group known as Fashion Nexus. In this context, Jaded London and AX Paris are among the mentioned example brands. Therefore, the user may have created an account, placed an order, or shared delivery information at affiliated fashion stores, even if they do not directly remember the name Fashion Nexus.\u003C\u002Fp>\u003Cp>The fields verified in this record are limited to the personal and account data above. Full payment card number, card security code, bank account, official identification document, or private message content are not among the verified data fields in this record. However, purchase history and address information, even if they are not payment card data, can indicate the user's real shopping behavior, delivery point, and communication channels. Therefore, the scope should be assessed more in terms of identity matching, account security, and targeted social engineering risk rather than financial card data.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The people at the highest risk are customers who use the same email and the same password at stores connected to the Fashion Nexus network. If the same password is also used for an email account, social media, shopping, shipping, non-bank payment, or work account, attackers may target other services using password trial lists. Users who, in particular, have not changed their old passwords for years, use a single password on multiple sites, and do not have two-factor authentication on their email account should be more careful.\u003C\u002Fp>\u003Cp>For customers with address and phone information, the risk is not limited to online account attempts. Attackers can pose as a shipping company, store customer service, returns department, or campaign team and prepare messages consistent with the person's past shopping information. Additional information such as date of birth and gender can also make it easier to guess authentication questions or generate messages that appear personalized. People who use the same contact information on multiple fashion sites should carry out the necessary checks, even if they do not clearly remember through which brand this incident affected them.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>The first step is to immediately change the password used in stores that may be associated with the Fashion Nexus network. If the same password has been used on another account, those accounts should also switch to a unique and strong password. Using a password manager makes it easier to set different and long passwords for each site. The email account should be prioritized for protection because password reset links for shopping accounts usually come through email. If two-factor authentication is not enabled on the email account, it should be activated immediately.\u003C\u002Fp>\u003Cp>The second step is to be careful with messages about old orders, deliveries, and returns. If the user is asked to click a link, open an attachment, make a payment again, confirm an address, or enter identity information, the authenticity of the message should be checked directly through the official domain of the relevant store. Even if people calling by phone know past order details, this alone is not proof of reliability. Urgent requests coming under the pretext of shipping, returns, or customer service should be calmly verified.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>This incident shows that old e-commerce accounts can continue to pose risks for a long time. Users should regularly close shopping accounts they no longer use, reduce stored address and phone information, and use different passwords for each store. Especially in accounts created years ago, there may be short passwords, repeated passwords, or email addresses that are no longer accessible. When such accounts are forgotten, risks that are noticed late after a leak may arise.\u003C\u002Fp>\u003Cp>On the corporate side, retail companies need to update their password storage methods with current strong algorithms, avoid keeping unnecessary personal data, be able to monitor customer records according to service provider distinctions, and conduct transparent communication after incidents. Older approaches like MD5 and SHA-1 do not provide sufficient protection even if the password data is in hashed form. If customer data circulates among multiple brands and technical service providers, responsibility boundaries and record life cycles must be clearly managed.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>The email address listed in this record may match a customer account used at Fashion Nexus or one of its affiliated fashion stores. If a match is found, the user should change the old password, update any other accounts where the same password is used, and check the login history of the email account. If any suspicious login, unexpected password reset notification, unknown order, or delivery change is noticed, contact the support channels of the relevant services.\u003C\u002Fp>\u003Cp>The correct approach to the Fashion Nexus data breach is not to see the incident merely as a problem of an old shopping site. When email, phone, address, purchase history, and password data are leaked simultaneously, the risk can reappear years later in phishing, account testing, and identity matching scenarios. Users should make permanent security habits of having unique passwords for each account, strong two-factor authentication, careful link checking, and reducing unnecessary old accounts.\u003C\u002Fp>","","Fashion Nexus Data Breach (1.3 Million Reported Records)","Fashion Nexus Data Breach. 1.3 Million reported records were reported. Reported data: Browser user agent details, Dates of birth, Email addresses. Review the…","\u002Fuploads\u002Flogo\u002Ffashionnexus_co_uk.webp",false,{"name":40,"sector":41,"country":42,"website":10,"websiteArchiveUrl":43,"websiteStatus":44,"websiteCheckedAt":45},"Fashion Nexus","Retail","United Kingdom","https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20190903120243\u002Fhttp:\u002F\u002Ffashionnexus.co.uk\u002F","archived","2026-07-29T11:30:22.391Z"]