[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2po3f69ny1wst":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":22,"affectedCountUnit":23,"hasEnglishDescription":4,"severity":24,"dataClasses":25,"description":32,"seoTitle":33,"seoTitleEn":34,"seoDescription":33,"seoDescriptionEn":35,"logoUrl":36,"isVerified":4,"isSensitive":37,"isSpamList":37,"isMalware":37,"company":38},"68e3266eda11adda48825283","locally","Locally Data Breach","locally.com","2022-10-01T00:00:00.000Z","2023-07-10T11:09:43.000Z","2023-07-10T11:12:48.000Z","2026-07-18T23:53:39.422Z","Website breach","https:\u002F\u002Ftwitter.com\u002Ftroyhunt\u002Fstatus\u002F1677855117960441858",[15,17,18,19],"https:\u002F\u002Fwww.twingate.com\u002Fblog\u002Ftips\u002Flocally-data-breach","https:\u002F\u002Fwww.locally.com\u002F","https:\u002F\u002Fjoin.locally.com\u002Fomnichannel-shopping-solution",362619,"known",null,"unknown","High",[26,27,28,29,30,31],"Email addresses","Partial credit card data","Passwords","Phone numbers","Physical addresses","Purchases","\u003Cp>The locally data breach is related to the exposure of customer data belonging to the locally.com service, which bridges brands, local stores, and online shoppers, in October 2022. The verified record affects 362,619 accounts. The data categories include email addresses, partial credit card data, password information, phone numbers, physical addresses, and purchase records. The password field should be considered bcrypt hashes; this does not mean that plain text passwords were visible.\u003C\u002Fp>\u003Cp>Locally, it is a retail technology service that combines online research with local store inventory, in-store pickup, local delivery, and brand referrals. Therefore, the impact of the incident is not limited to account login risk alone. When purchase history, phone, address, and partial card information are seen together, fake delivery notifications, order changes, returns, card verification, or customer support messages can become more convincing. User action should include both account security and financial transaction control.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The main types of data verified in this record are email addresses, phone numbers, physical addresses, purchase records, partial credit card information, and password data. Partial card information refers to limited fields such as card type and the last four digits; the full card number or card security code is not a verified field in this record. Password data is represented as bcrypt hashes. A strong hash format does not directly mean a plaintext password, but the risk persists for weak or reused passwords.\u003C\u002Fp>\u003Cp>The appearance of email, phone, and physical address within the same record increases the likelihood of targeted social engineering. Purchase information can show the attacker which product, store, or order scenario can be associated with the user. Partial card information alone may not be sufficient to make a payment, but it can be used as a trust signal in fake bank or refund discussions. Therefore, the risk should be assessed under account takeover, phishing, card activity monitoring, and address-based fraud categories.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The verified scope is the Locally incident for the October 2022 period and 362,619 affected accounts. The record was included as verified in the large breach data sets in July 2023. The data class list consists of six main areas: email addresses, partial credit card data, passwords, phone numbers, physical addresses, and purchase records. It is stated that the company specifically acknowledged the breach, but it is not clearly known whether notifications were sent to the affected customers.\u003C\u002Fp>\u003Cp>In this record, full credit card numbers, card security codes, bank accounts, official identification numbers, or health data should not be included as verified fields. The technical entry point of the incident is also not confirmed; specific claims of a vulnerability, malware, or employee account should not be presented as definite facts. The record should be addressed with a focus on customer accounts and transaction data. In this way, the user acts based on the risks created by actual observed data fields, rather than unverified scenarios.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The highest risk applies to people who search for products from local stores via Locally, place orders, and use the delivery or in-store pickup option. If the same email and phone information is used in other shopping accounts, an attacker may try to match the person across different services. The physical address can associate the user with a specific city, store area, or delivery route. Purchase history also makes targeted messages appear more realistic.\u003C\u002Fp>\u003Cp>Retail employees, store representatives, frequent shoppers, those who use the same password on multiple accounts, and people who do not regularly monitor card transactions should be more careful. Partial card information can be used especially in fake support calls that ask the user to provide the remaining digits of their card. Although Bcrypt password hashes provide strong protection, short, predictable, or previously used passwords carry additional risk. Therefore, accounts with repeated passwords should be checked as a priority.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>If you have a local account, change your password to a unique and long one. If the same or similar password is used on other shopping, email, social media, or payment accounts, choose a different new password for each account. Two-factor authentication should be enabled on accounts that support it, and registered sessions and account recovery options should be checked. Even if the password is seen as a hash, if the password is reused, an attacker may still try it on different sites.\u003C\u002Fp>\u003Cp>Review your credit card transactions and be cautious of calls, SMS, or emails that come with card type or the last four digits information. If a message comes on behalf of a bank or store requesting order, delivery, return, or card verification, the official app or known website address should be used instead of clicking a link. Since address and phone information are also visible, unexpected shipping, in-store pickup, or customer support calls should be verified through another channel. If there is a suspicious payment or order activity, contact the card provider and the relevant store directly.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, a separate email alias, unique password, and, if possible, payment notifications should be used for shopping accounts. Not keeping unnecessary saved cards, old addresses, and old phone information in the browser or store accounts reduces data visibility. Messages containing order and delivery information should always be checked from official accounts; a person who knows the last four digits of a card should not be assumed to be a bank or store employee.\u003C\u002Fp>\u003Cp>Using a password manager makes it easier to find recurring passwords and generate strong passwords for each service. Since the email account plays a central role, the security of this account should also be strengthened. Instant notifications from the card provider, spending limits, and virtual card options can be preferred. Old retail records can be reused in fraud messages even years later; for this reason, regular account cleaning and transaction tracking should be a permanent security routine.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>If the result for Locally appears positive on LeakData, this record is associated with the exposure of Locally customer and shopping data in October 2022. The first step should be to find the account used with Locally or the affiliated store experience with the relevant email address. Then, it should be checked one by one whether the password has been used elsewhere, whether the registered phone and address information is up to date, and whether there are any unusual transactions in card activity.\u003C\u002Fp>\u003Cp>The verified data classes for this breach record are email addresses, partial credit card data, password information, phone numbers, physical addresses, and purchase records. Password data should be considered as bcrypt hashes; full card numbers, card security codes, bank account numbers, or official ID numbers are not verified fields of this record. User actions should focus on password reuse, targeted phishing, address-based social engineering, and card activity monitoring.\u003C\u002Fp>","","Locally Data Breach (362.6 Thousand Reported Records)","Locally Data Breach. 362.6 Thousand reported records were reported. Reported data: Email addresses, Partial credit card data, Passwords. Review the scope…","\u002Fuploads\u002Flogo\u002Flocally_com.webp",false,{"name":39,"sector":40,"country":41,"website":9,"websiteArchiveUrl":33,"websiteStatus":33,"websiteCheckedAt":22},"Locally","Retail Technology","United States"]