[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1i9dfn1lvzqf0":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":11,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":30,"seoTitle":31,"seoTitleEn":32,"seoDescription":31,"seoDescriptionEn":33,"logoUrl":34,"isVerified":4,"isSensitive":35,"isSpamList":35,"isMalware":35,"company":36},"68e3266eda11adda488252a6","meo","MEO Data Breach","meoair.com","2020-12-24T00:00:00.000Z","2023-04-24T02:39:49.000Z","2026-07-18T23:54:15.002Z","Face mask ecommerce breach","https:\u002F\u002Fmeoair.com\u002F",[14,16],"https:\u002F\u002Fwww.nzstory.govt.nz\u002Fabout-us\u002Fnews\u002Fmeo-face-mask",8227,"known",null,"unknown","Low",[23,24,25,26,27,28,29],"Email addresses","Names","Passwords","Phone numbers","Physical addresses","Purchases","Usernames","\u003Cp>The MEO data breach is an account security incident affecting customer records dating back to December 24, 2020, associated with a New Zealand-based face mask brand. The breach came to light in 2023 with a discovered dataset, and 8,227 customer records were verified. The verified data categories include email addresses, full names, passwords, phone numbers, physical addresses, purchase information, and usernames. The password field is stored in the MD5 WordPress hash format; since this format is considered weak by modern security standards, reusing the same or similar password on other accounts poses a separate risk.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>In this record, the customer ID, contact information, and purchase history are combined in the same dataset. When the email address, full name, phone number, and physical address are considered together, delivery, return, payment, warranty, or product information messages that appear realistic to the user can be sent. Purchase information can indicate a person's shopping preferences related to mask and filter products. The username can help match the same person with other e-commerce or forum accounts.\u003C\u002Fp>\n\u003Cp>It is particularly important that the password data is in MD5 WordPress hash format. This does not mean that the password is in plain text; however, the old hash format does not provide sufficient resistance for weak passwords. Short passwords, those found in dictionaries, containing personal information, or reused on other services are easier to guess. Therefore, the risk in the MEO record is not limited to a retail account; if the same password habit is used in email, shopping, social media, or work accounts, there is a possibility of chain account compromise.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>Verified scope; meoair.com domain, December 24, 2020 violation date, April 24, 2023 addition date, and 8,227 affected customer records. Reliable records identify MEO as a New Zealand-based face mask company. Therefore, it is more accurate to list the company's country as New Zealand instead of the United States, and its sector as protective face masks and e-commerce instead of general retail. The site is currently accessible today with online sales and product pages.\u003C\u002Fp>\n\u003Cp>For this record, payment card number, bank account, identity document, date of birth, or sensitive health data are not among the verified data classes. Purchase information exists, but this information should not be confused with payment card data. Since there is no definite and detailed public record regarding the technical reason, the explanation should be limited to verified data fields and user impact. Information that the institution did not respond to notification attempts can be kept in an internal source note; in the user-facing section, the main risk is which data was exposed and what kind of measures are needed.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk is among customers who reuse the password they use for their MEO account on other accounts. People who use the same email and password combination for their email account, other shopping sites, courier services, or payment-related accounts in particular should take precautions quickly. Customer records containing physical addresses and phone numbers can make fake calls and messages that come under the pretext of delivery more convincing. The username can also lead to connections with old e-commerce or forum records.\u003C\u002Fp>\n\u003Cp>Customers who purchase face masks and filters may become susceptible to targeted advertising, fake campaigns, and product return fraud due to periodic health or protective product needs. Purchase history can help attackers craft subject lines that appear personal, such as 'your order,' 'your shipping address,' 'your return request,' or 'your filter replacement subscription.' Although this dataset may seem small, the combination of address, phone number, purchase, and password information increases the practical risk to the user.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>Users who see an MEO match should first change the password they use on their MEO account and all accounts where they use the same or similar password. New passwords should be unique and stored with a password manager. The email account should be prioritized for protection, as password reset links and order notifications usually come to the same inbox. Two-factor authentication should be enabled on the email account, recovery options should be checked, and unknown sessions should be closed.\u003C\u002Fp>\n\u003Cp>Users should be careful with messages that come under the pretext of cargo, returns, mask filters, warranty, order cancellation, or payment verification due to address, phone, and purchase information. Instead of opening a login form from the link in the message, the relevant site should be visited directly. If order number, address, payment information, or security code is requested during phone calls, the process should be stopped and verified through the institution's official communication channel. When a suspicious order or cargo notification is received, a screenshot should be saved and account security steps should not be delayed.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>This incident shows that even small customer data sets can create multidimensional risks. Users should not reuse the same password for shopping accounts, should not leave their delivery addresses stored in unnecessary services, and should close store accounts they no longer use. It is important for retail accounts to have email addresses, phone numbers, and address information up to date but kept at a minimum level. A password manager provides an additional layer of protection to the email account while generating strong and unique passwords.\u003C\u002Fp>\n\u003Cp>For service providers, password hash format, data minimization, and notification management are critical topics. Old MD5-based hash formats should be abandoned, strong password storage methods should be used, and unnecessary customer data should not be retained for a long time. On the e-commerce side, purchase, address, and phone information should be protected with limited access; when a security notification is received, quick verification and user notification should be provided. Customer trust is maintained not only during the sale but also during the data security and post-breach communication process.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>If you see a MEO match on LeakData, consider it as a 2020 incident of face mask e-commerce customer data breach. The match indicates that your email address, full name, phone number, physical address, purchase information, username, and password in MD5 WordPress hash format may have been included in this record. The first step is to separate all accounts where you use the same password and strengthen your email account.\u003C\u002Fp>\n\u003Cp>Pay special attention to delivery and order-themed fraud risks for this record. Messages containing details such as the shipping address, filtered product, mask order, or return request should not be considered trustworthy, even if they appear personal. Check the domain before opening a link, do not enter information in forms requesting payment or security codes, and end conversations in suspicious calls. The lesson is also clear for institutions: it is necessary to prevent employees from reusing passwords from shopping accounts on work accounts and to regularly organize email-focused phishing trainings.\u003C\u002Fp>","","MEO Data Breach (8.2 Thousand Reported Records)","MEO Data Breach. 8.2 Thousand reported records were reported. Reported data: Email addresses, Names, Passwords. Review the scope, risks, and protective steps.","\u002Fuploads\u002Flogo\u002Fmeoair_com.webp",false,{"name":37,"sector":38,"country":39,"website":9,"websiteArchiveUrl":31,"websiteStatus":31,"websiteCheckedAt":19},"MEO","Protective Face Masks \u002F Ecommerce","New Zealand"]