[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fw9u28pav06n":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":30,"seoTitle":16,"seoTitleEn":31,"seoDescription":16,"seoDescriptionEn":32,"logoUrl":33,"isVerified":4,"isSensitive":34,"isSpamList":34,"isMalware":34,"company":35},"68e3266eda11adda4882528f","lu-lu","LuLu Data Breach","lulu","luluhypermarket.com","2024-07-06T00:00:00.000Z","2024-08-02T02:59:07.000Z","2026-07-03T14:44:07.173Z","2026-07-18T23:53:49.363Z","Third party breach","",[],2796835,"known",null,"unknown","Critical",[24,25,26,27,28,29],"Email addresses","Names","Passwords","Phone numbers","Physical addresses","Purchases","\u003Cp>The LuLu data breach is an incident from July 2024 involving customers of the UAE-based large retail chain LuLu Hypermarket. Initial reports highlighted hundreds of thousands of customer records, and later, with a larger backup dataset, the total scope reached approximately 2.8 million unique email addresses. The records include email addresses, names, hashed passwords, phone numbers, physical addresses, and purchase information.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>In this incident, the presence of a password field along with contact information significantly increases the risk. Even if passwords are not listed in plain text, hashed passwords can be attempted to be cracked by attackers, and if the same password is used on other accounts, it can lead to account takeover attempts. Email, phone, and address fields also allow the user to be targeted through different channels.\u003C\u002Fp>\u003Cp>Purchase information can provide clues about the user's shopping history and delivery context. This information can be used in messages themed around fake shipping, returns, grocery coupons, membership points, order updates, or product delivery. Full payment card data is not listed in this record; however, when shopping and address context are combined, fraud attempts can become more convincing.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The record shows the incident date as July 6, 2024, with the number of affected records recorded as 2,796,835. Publicly available security news initially indicates that data of approximately 196 thousand customers was shared, and later a larger database backup also emerged. The existing data classes are compatible with this expanding scope, and the record is kept in a verified status.\u003C\u002Fp>\u003Cp>While explaining the scope, two levels should be distinguished: the first visible leak contains limited customer information, and the subsequent larger data set includes more email and order context. Not all fields are expected to be present in each row. Additionally, the presence of hashed passwords does not mean the user's password is automatically known; however, it requires urgent measures against password reuse.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Users at risk are customers who have created an account, placed an order, or shared their phone number and delivery address on the LuLu online store or associated digital shopping channels. The risk is higher for those who use the same password on email, bank, social media, or other shopping accounts.\u003C\u002Fp>\u003Cp>Since retail and grocery shopping are areas frequently engaged in, users are accustomed to messages about delivery, promotions, or loyalty programs. Attackers may use themes such as order numbers, delivery delays, or discount coupons in fake messages sent with real names and phone numbers. For this reason, links in SMS and messaging apps should be evaluated carefully.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users in the matching field should immediately change the password for their LuLu account and separate all accounts where the same password is used one by one. Generating a unique password with a password manager is the most important step to prevent this incident from spreading to other accounts. Two-factor authentication should be enabled on every possible account.\u003C\u002Fp>\u003Cp>For messages requesting cargo tracking, refunds, membership points, gift vouchers, or payment corrections, the process should be verified through the official app or a known web address before clicking any links. Even if the caller knows your name, address, or previous order information, verification codes and payment information should not be shared. If a suspicious transaction is observed, the bank and the relevant platform should be informed through a separate channel.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, password reuse on retail accounts should be completely avoided. Using different email aliases for shopping sites makes it easier to understand which platform is the source of a risk. Cleaning up unused addresses, old phones, and unnecessary saved delivery information also reduces the amount of data that could be exposed in future breaches.\u003C\u002Fp>\u003Cp>In breaches involving hashed password data, it is not sufficient to protect only the affected store account. The user's email account, payment services, shipping accounts, and all services where the same password is used should be evaluated separately. Account recovery email and phone number should be kept up to date, and suspicious login alerts should be enabled.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>The check performed on LeakData shows whether the user's email address appears in the data associated with the LuLu breach. If a positive result is obtained, the user should immediately eliminate password reuse and be cautious of fake shipping and campaign messages, assuming that their phone and address information could be misused.\u003C\u002Fp>\u003Cp>A negative result means that there is no match within this record; it does not prove that the user is secure across all retail accounts. It should be periodically checked whether the same email address appears in different violations, and strong passwords and two-step verification should be standardized for shopping accounts.\u003C\u002Fp>","LuLu Data Breach (2.8 Million Reported Records)","LuLu Data Breach. 2.8 Million reported records were reported. Reported data: Email addresses, Names, Passwords. Review the scope, risks, and protective steps.","\u002Fuploads\u002Flogo\u002Fluluhypermarket_com.webp",false,{"name":36,"sector":37,"country":38,"website":10,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":20},"LuLu","Retail","United Arab Emirates"]