[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fey7gp26oxgza":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":22,"affectedCountUnit":23,"hasEnglishDescription":4,"severity":24,"dataClasses":25,"description":32,"seoTitle":33,"seoTitleEn":34,"seoDescription":33,"seoDescriptionEn":35,"logoUrl":36,"isVerified":4,"isSensitive":37,"isSpamList":37,"isMalware":37,"company":38},"68e3266eda11adda48825267","lazada-redmart","Lazada RedMarch Data Breach","redmart.lazada.sg","2020-07-30T00:00:00.000Z","2020-11-10T00:58:49.000Z","2020-11-10T01:01:56.000Z","2026-07-18T23:53:15.553Z","Website breach","https:\u002F\u002Fredmart.lazada.sg\u002F",[15,17,18,19],"https:\u002F\u002Ffiles.app.optical.gov.sg\u002Fpdpc\u002Fproduction\u002Fassets\u002F438fd68d-bcd9-4d25-8f77-09268e80a4e4.pdf","https:\u002F\u002Fwww.straitstimes.com\u002Ftech\u002Fpersonal-information-of-11-million-redmart-users-stolen-in-lazada-data-breach","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fover-1m-lazada-redmart-accounts-sold-online-after-data-breach\u002F",1107789,"known",null,"unknown","Critical",[26,27,28,29,30,31],"Email addresses","Names","Partial credit card data","Passwords","Phone numbers","Physical addresses","\u003Cp>The Lazada RedMart data breach is a 2020 confirmed e-commerce incident affecting the former customer data of RedMart's online grocery service in Singapore. The main metric tracked in the record is 1,107,789 accounts or email entries. The incident is referred to as Lazada RedMart because RedMart operates within Lazada; however, the verified scope is not general Lazada accounts or all Lazada customers in the region, but former customer data associated with RedMart. Records show that the most recent data time extends to July 2020, the incident became public in October 2020, and was later addressed in the Singapore data protection review with a separate individual metric. Therefore, when assessing user impact, the account\u002Femail count should not be read as the same metric as the individual count in the official review.\u003C\u002Fp>\n\u003Cp>This record increases social engineering risks for users who have a RedMart shopping account through phishing, password reuse, delivery address targeting, and partial card data. Passwords are stored as SHA-1 hashed values rather than in plain text; however, this alone is not sufficient protection for weak or previously reused passwords. The exposed payment information is limited to partial credit card data; it does not include the full card number, CVV, bank account, passport, health data, or official ID number within the verified scope.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The data classes confirmed in the Lazada RedMart leak include email addresses, first and last names, phone numbers, physical addresses, partial credit card data, and password hashes. This dataset alone does not directly mean full payment access; however, when the customer's name, delivery address, phone, and email are combined, highly convincing fake orders, fake support requests, and account security messages can be generated. Since the partial card data may include parts such as the first six and last four digits, the cardholder's name, expiration date, or billing contact fields, users need to monitor their statements and notifications more carefully.\u003C\u002Fp>\n\u003Cul>\u003Cli>\u003Cstrong>Email addresses:\u003C\u002Fstrong> Can be used for RedMart and Lazada-themed phishing, fake discounts, fake delivery notifications, and account recovery messages.\u003C\u002Fli>\u003Cli>\u003Cstrong>Name, phone, and address:\u003C\u002Fstrong> Increases personal targeting power; a scammer may try to persuade the user by imitating the language of real orders and deliveries.\u003C\u002Fli>\u003Cli>\u003Cstrong>Password hashes:\u003C\u002Fstrong> SHA-1 is an old method that can be cracked quickly. The risk of account takeover increases for people who use the same password on other accounts.\u003C\u002Fli>\u003Cli>\u003Cstrong>Partial credit card data:\u003C\u002Fstrong> Does not mean full card information; nevertheless, it can be misused in scenarios such as fake bank call, card renewal pretext, or counterfeit payment confirmation.\u003C\u002Fli>\u003Cli>\u003Cstrong>Physical addresses:\u003C\u002Fstrong> When combined with delivery and billing information, it increases the risk of home address-focused harassment, targeted messaging, and identity verification bypass.\u003C\u002Fli>\u003C\u002Ful>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified breach record tracks the date July 30, 2020, and the impact at the level of 1,107,789 accounts\u002Femails. Period reports stated that RedMart data was put up for sale and the records extend until July 2020. In the official data protection decision in Singapore, it is noted that the data was taken out on September 6, 2020, affecting 898,791 individuals. These two numbers represent different measurement levels: one is an account or email-focused index metric, the other is the individual metric used in the official review. Therefore, the record should maintain the total of 1,107,789 entries, and the official individual count should be read as a separate scope note in the explanation.\u003C\u002Fp>\n\u003Cp>Scope is limited to RedMart's old customer and vendor data. It should not be presented as a verified claim that current Lazada customer data or the entire Lazada regional account has been compromised. RedMart's acquisition by Lazada explains the name connection; however, the verified dataset of the leak pertains to records from RedMart's old systems. Additionally, data types such as social security number, passport, health information, full card number, CVV, or bank account should not be added to this record outside of the verified fields.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk is for users who reuse the password they use for their RedMart account on email, shopping, banking, social media, or work accounts. Even if the password hashes are not in plain text, SHA-1 is an old and fast hash type that can be tried, so weak, short, or previously leaked passwords can be quickly guessed. For people who log into many services with the same email address, this record can turn into a much broader account security problem than a single shopping account.\u003C\u002Fp>\n\u003Cp>Users whose address and phone information is leaked are also more susceptible to targeted fraud. Fraudsters can combine real names, real delivery addresses, and partial card information to create fake customer service, fake returns, fake delivery fee, account suspension, or card verification scenarios. People who have not shopped from RedMart for a long time should not be considered risk-free either; because old data sets can be used for phishing and profile matching even years later.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>Immediately change the password you have previously used on your RedMart or Lazada account to a unique and strong password. If you have used the same or a similar password on other services, update those accounts separately as well. Priority should be given to email accounts, financial services, shopping accounts, social media, and work accounts. Simply renewing the password with a small change is not sufficient; if the old password carries a predictable pattern, attackers may try these variations as well.\u003C\u002Fp>\n\u003Col>\u003Cli>\u003Cstrong>Enable multi-factor authentication:\u003C\u002Fstrong> Use app-based authentication or a security key on every supported account.\u003C\u002Fli>\u003Cli>\u003Cstrong>Monitor statements:\u003C\u002Fstrong> Due to partial card data, pay attention to small and unfamiliar transactions on the card.\u003C\u002Fli>\u003Cli>\u003Cstrong>Do not trust fake support messages:\u003C\u002Fstrong> If you are asked for a password, one-time code, full card number, or CVV, stop the process.\u003C\u002Fli>\u003Cli>\u003Cstrong>Reduce address and phone risks:\u003C\u002Fstrong> Do not open links sent under the pretext of delivery, returns, or taxes outside the official app or official website.\u003C\u002Fli>\u003Cli>\u003Cstrong>Check account sessions:\u003C\u002Fstrong> If there is an unfamiliar device, a new delivery address, a change in registered card, or a suspicious order attempt, lock the account.\u003C\u002Fli>\u003C\u002Fol>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>This incident shows that e-commerce accounts carry not only shopping history but also identity, address, phone, and payment context. In the long term, it is necessary to use a unique password for each shopping site, generate random values with a password manager, and protect the email account at a separate high security level. Regularly reviewing old accounts, closing unused registrations, and reducing saved cards reduces personal risk exposure.\u003C\u002Fp>\n\u003Cp>It is important for users to evaluate the messages they receive in context to prevent misuse of address and phone information. A message should not be considered trustworthy just because it knows your real name, delivery neighborhood, or the last four digits of your card. The lesson for the corporate side is also clear: customer data remaining from old systems carries an active risk that must be protected, even if it is separated from the live customer flow. Authority limits, separate authentication, avoiding unnecessary data storage, strong logging, and rapid notification processes reduce the impact of such incidents.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>If your email address matches in this record, first check your RedMart\u002FLazada history and any other accounts where you use the same password. A match does not mean that your full card details or your entire Lazada account have been compromised; the verified scope includes old customer data associated with RedMart, partial card data, and password hashes. Nevertheless, action should be taken in terms of phishing, account takeover, and targeted fraud.\u003C\u002Fp>\n\u003Cp>Even if there is no record, if you have used RedMart before, it makes sense to take basic precautions: unique password, multi-factor authentication, statement monitoring, caution against suspicious messages, and deleting unnecessary saved cards. If your email address appears in this leak, there is no need to panic; however, continuing to use the same password elsewhere increases the risk. A secure approach is to isolate the affected account, disconnect password links with other accounts, and be more selective against social engineering attempts using your phone or address information.\u003C\u002Fp>","","Lazada RedMarch Data Breach (1.1 Million Reported Records)","Lazada RedMarch Data Breach. 1.1 Million reported records were reported. Reported data: Email addresses, Names, Partial credit card data. Review the scope…","\u002Fuploads\u002Flogo\u002Fredmart_lazada_sg.webp",false,{"name":39,"sector":40,"country":41,"website":9,"websiteArchiveUrl":33,"websiteStatus":33,"websiteCheckedAt":22},"Lazada RedMart","Online Grocery","Singapore"]