[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fv3uupf2o0omo":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":29,"seoTitle":15,"seoTitleEn":30,"seoDescription":15,"seoDescriptionEn":31,"logoUrl":32,"isVerified":4,"isSensitive":33,"isSpamList":33,"isMalware":33,"company":34},"68e3266eda11adda48825352","robinsons-malls","Robinsons Malls Data Breach","robinsonsmalls.com","2024-06-01T00:00:00.000Z","2025-06-25T14:22:15.000Z","2026-07-03T23:38:27.452Z","2026-07-18T23:57:25.651Z","Third party breach","",[],195597,"known",null,"unknown","High",[23,24,25,26,27,28],"Dates of birth","Email addresses","Genders","Geographic locations","Names","Phone numbers","\u003Cp>The Robinsons Malls data breach is related to the exposure of mobile application user data of the shopping mall operator operating in the Philippines during June 2024. The scope is approximately 195,597 unique email addresses. This record was treated as a mobile app and retail customer data breach; the company, country, industry, website, and data class fields have been realigned with the verified scope. The country was corrected from United States to Philippines.\u003C\u002Fp>\u003Cp>The text was rewritten to explain the risk, scope, and actions directly to the user. The website domain was kept as robinsonsmalls.com; a format was not used that would cause https to appear twice on the link because the protocol was not added. The industry was clarified as retail and shopping mall operator; the incident was limited to the context of a mobile application.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data seen in this record are birth dates, email addresses, gender information, geographic locations, names, and phone numbers. Password or payment card field was not verified. Unverified payment card, bank account, private message, health record, or additional profile fields were not added to the data class list; only the supported fields were left.\u003C\u002Fp>\u003Cp>City, province, phone number, and date of birth information can make fake campaign, loyalty program, store event, or reward messages more convincing. An email address alone creates a risk of unwanted messages; when combined with phone number, address, IP, date of birth, password, official ID, support record, vehicle information, or physical address, it becomes easier for an attacker to produce messages personalized for the user. The risk assessment was conducted based on this combined effect.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The scope was verified with 195,597 records dated June 2024. Confirmed areas were preserved while unconfirmed areas were excluded. The event was not combined with datasets with similar names, events from different periods of the same company, or incorrect industry references.\u003C\u002Fp>\u003Cp>The registration is limited to Robinsons Malls mobile application user data and was not presented as a payment system breach. The domain name, company name, and industry information were kept in the narrowest accurate context possible. In areas of uncertainty, a verified flag or website field was set accordingly; thus, the user was not shown brand responsibility that was not certain.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>User groups at risk may be users who have the Robinsons Malls mobile application or a loyalty\u002Fevent account. Matched users should also evaluate other accounts where they use the same email, phone number, username, or password pattern outside the relevant service.\u003C\u002Fp>\u003Cp>Shopping mall events and promotions may appear more persuasive when personalized with phone and location information. If there is a context of corporate email, gaming forum, motorcycle customer registration, shopping mall application, support request, rental account, marketing list, or malware, the risk of social engineering may increase. Details that appear correct alone are not a sign of trust.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users should verify campaign, reward, event, and phone verification messages through the official app or website. For records with a password field, all accounts using the same password should be updated; for records without a password field, focus should be on the risks of email, phone, fake notifications, privacy, and identity matching.\u003C\u002Fp>\u003Cp>Instead of clicking on the links in the message, the address of the relevant service should be typed manually or the record in a trusted password manager should be used. Invoice, account warning, game reward, support, shipping, customer service, maintenance appointment, public notice, or subscription renewal messages should not be accepted without verification through an independent channel.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In retail mobile applications, sharing of date of birth, phone number, and location should be kept to a minimum. Users should regularly clean up old accounts, unnecessary profile fields, duplicate usernames, and old phone and address information. A unique password for each service and two-step verification where possible should be a basic rule.\u003C\u002Fp>\u003Cp>From the perspective of service providers, data minimization, strong password protection, monitoring of access logs, deletion of unnecessary fields, and readiness of user notification processes are required. Mobile retail applications should not combine campaign data with customer identity for longer than necessary. Proper scope description is also part of the security effort; exaggerated or incomplete information can mislead the user into incorrect actions.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>The user should first check this record using the email address. If a match is found, it should be accepted that the phone number, date of birth, city\u002Fprovince, and name information can be used in targeted campaign messages. Not finding a match does not completely exclude the use of a different email or the reuse of an old password; critical accounts should also be reviewed.\u003C\u002Fp>\u003Cp>This record remained verified; unverified password or payment fields were not added. In this edit, data fields were left as English canonical classes, the description visible to the user was written in Turkish and original, unverified fields were not added, and the sensitivity flag was used only when supported by the risk context.\u003C\u002Fp>","Robinsons Malls Data Breach (195.6 Thousand Reported Records)","Robinsons Malls Data Breach. 195.6 Thousand reported records were reported. Reported data: Dates of birth, Email addresses, Genders. Review the scope, risks…","\u002Fuploads\u002Flogo\u002Frobinsonsmalls_com.webp",false,{"name":35,"sector":36,"country":37,"website":9,"websiteArchiveUrl":15,"websiteStatus":15,"websiteCheckedAt":19},"Robinsons Malls","Retail \u002F Shopping Mall Operator","Philippines"]