[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2md4odv5tkovv":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":29,"seoTitle":30,"seoTitleEn":31,"seoDescription":30,"seoDescriptionEn":32,"logoUrl":33,"isVerified":4,"isSensitive":34,"isSpamList":34,"isMalware":34,"company":35},"68e3266eda11adda48825215","HauteLook","HauteLook 2018 Data Breach","hautelook","hautelook.com","2018-08-07T00:00:00.000Z","2019-03-21T21:57:32.000Z","2026-07-21T17:35:40.334Z","Verified breach record","https:\u002F\u002Fwww.theregister.com\u002F2019\u002F02\u002F11\u002F620_million_hacked_accounts_dark_web\u002F",[15],28510459,"known",null,"unknown","Critical",[23,24,25,26,27,28],"Dates of birth","Email addresses","Genders","Geographic locations","Names","Passwords","\u003Cp>\u003Cstrong>The HauteLook data breach\u003C\u002Fstrong> is a verified event associated with the online fashion-shopping service and dated August 7, 2018. The canonical scope contains 28,510,459 unique accounts. The record lists dates of birth, email addresses, genders, geographic locations, names, and passwords protected with bcrypt hashes. This combination can create a greater personalization and account-takeover risk than an email-only exposure.\u003C\u002Fp>\u003Cp>Data associated with the event was reported as offered for sale in early 2019. The verified record does not establish the precise initial access method, which profile fields were present for every account, or whether payment systems were affected. A match means that an email address falls within the verified scope; it does not show that card details were seen, that an account remains open today, or that every field was available for the same person.\u003C\u002Fp>\u003Ch2>Exposed Data Types and Risks\u003C\u002Fh2>\u003Cp>The verified classes are dates of birth, email addresses, genders, geographic locations, names, and password hashes. When placed together, these fields can help create email, text-message, or support requests that appear tailored to a customer. Name, birth-date, and location context can make deceptive contact about delivery issues, discount offers, membership renewal, or payment verification seem more convincing.\u003C\u002Fp>\u003Cp>Passwords were listed as bcrypt hashes rather than readable plain text. That does not mean they were directly visible, but weak or reused passwords can still create risk over time. A match with a password hash does not prove that a current password was recovered. The right security decision depends on password reuse and the current protection of the accounts involved.\u003C\u002Fp>\u003Cp>The verified classes do not include payment-card numbers, phone numbers, or physical addresses. That does not mean no other record at the service was affected; it only marks the boundary of this verified event. Nor should every data type be assumed to appear in every match. People should treat a match as a personal risk signal and not treat unproven details as facts.\u003C\u002Fp>\u003Ch2>Verified Scope and Limits\u003C\u002Fh2>\u003Cp>The date on this page is August 7, 2018, and the canonical record count is 28,510,459. That figure represents a verified email scope; it is not a total of all customers ever served, active accounts, or the current user base. Because the same email address can appear in more than one record, a record total cannot be translated directly into a count of individual people.\u003C\u002Fp>\u003Cp>HauteLook is classified as a fashion-focused online shopping service. This event is associated with that one service, and other brands or shopping sites that may belong to a related business group do not enter the scope automatically. A person appearing in a HauteLook record is not proof that they held an account at another retailer or that other accounts were affected by this event.\u003C\u002Fp>\u003Cp>The verified information does not establish the starting point of the intrusion, the identity of an attacker, when every data file was copied, or which customers received notice. The date identifies the period associated with the event; by itself, it does not show when the data first appeared online or when each account was last used. These uncertainties do not reduce the importance of the event, but they require care with technical claims that cannot be confirmed.\u003C\u002Fp>\u003Ch2>Users at Elevated Risk\u003C\u002Fh2>\u003Cp>People who reused a HauteLook password at another shopping, email, or social account deserve the highest priority. Bcrypt protection does not eliminate password risk; short, predictable, or reused passwords can be tried against other systems. Anyone who signs into many services with the same email address should review password habits, especially for older memberships.\u003C\u002Fp>\u003Cp>People matched with a birth date, name, and geographic context should be alert to personalized fraud. An attacker may use these details in messages about delivery delays, loyalty points, coupons, membership renewal, or order confirmation. Personal details in a message do not prove that its sender is a legitimate retailer.\u003C\u002Fp>\u003Cp>Older shopping accounts that are no longer in active use also deserve consideration. The registered email address may still be a recovery point for newer services. People using the same mailbox should inspect unfamiliar sessions, forwarding rules, recovery options, and unexpected password-reset notices carefully.\u003C\u002Fp>\u003Ch2>Immediate Protective Actions\u003C\u002Fh2>\u003Cp>First, when a password used at HauteLook was also used elsewhere, change those other passwords to unique, strong values. If the account remains accessible, change its password as well and enable multi-factor authentication where the option exists. Email accounts are recovery points for many services, so the mailbox password and recovery details need priority review.\u003C\u002Fp>\u003Cp>Check account activity and the email inbox for unusual events. When an unfamiliar sign-in notice, coupon offer, order alert, or password-reset message arrives, inspect the sender domain and requested action before opening a link. To confirm an alert, go directly to the known official address of the service rather than following the address supplied in the message.\u003C\u002Fp>\u003Cp>Use the official support channel of the relevant service when suspicious activity appears. Remove access when account settings show an unfamiliar device, session, recovery address, or connected application. Payment-card details are not among the verified classes, yet it remains prudent to monitor bank and card alerts for unusual activity when an online shopping account has a saved payment method.\u003C\u002Fp>\u003Ch2>Long-Term Security Practices\u003C\u002Fh2>\u003Cp>Using a different, long password for every shopping site and online service is one of the strongest protections. A password manager can generate random passwords and reduce reuse. Where multi-factor authentication is available, an authenticator application or hardware key is preferable; text-message codes add protection but cannot prevent every convincing fraud attempt.\u003C\u002Fp>\u003Cp>Limit disclosure of nonessential profile fields such as birth date, gender, location, and contact preferences in shopping accounts. Reviewing visible profile details and saved addresses in older accounts leaves less context for future targeting. Reducing third-party sharing in service privacy settings can also limit unnecessary distribution of personal information.\u003C\u002Fp>\u003Cp>Review account-recovery security at regular intervals. Secondary email addresses, phone numbers, connected devices, and sessions need to remain current. Keep sign-in alerts enabled where practical, and respond quickly when an unfamiliar session or address change appears. These habits protect every customer account, not only people matched with this event.\u003C\u002Fp>\u003Ch2>Record Check and User Action\u003C\u002Fh2>\u003Cp>Use the record check on this page to see whether your email address matches the HauteLook event. A match indicates that the address is within the verified scope; it does not prove that every data type appeared in your row, that a password was recovered, or that a current account was compromised. Use the result as a personal risk signal to prioritize password reuse and account-recovery settings.\u003C\u002Fp>\u003Cp>If there is no match, it can still be useful to recall older email addresses, alternate registrations, and closed shopping accounts. No match is not a guarantee that no personal information exists elsewhere online. Unique passwords, multi-factor authentication, routine account review, and independent confirmation of suspicious messages remain the most reliable defense.\u003C\u002Fp>","","HauteLook 2018 Data Breach (28.5 Million Reported Records)","HauteLook 2018 Data Breach. 28.5 Million reported records were reported. Reported data: Dates of birth, Email addresses, Genders. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fhautelook_com.webp",false,{"name":7,"sector":36,"country":37,"website":10,"websiteArchiveUrl":30,"websiteStatus":30,"websiteCheckedAt":19},"Fashion E-commerce","United States"]