[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1dw7dp7byhpc9":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":31,"seoTitle":15,"seoTitleEn":32,"seoDescription":15,"seoDescriptionEn":33,"logoUrl":34,"isVerified":4,"isSensitive":35,"isSpamList":35,"isMalware":35,"company":36},"68e3266eda11adda488253a6","t2","T2 Data Breach","t2tea.com","2024-04-17T00:00:00.000Z","2024-04-22T06:17:17.000Z","2026-07-03T15:04:46.003Z","2026-07-18T23:59:00.981Z","Third party breach","",[],94584,"known",null,"unknown","Medium",[23,24,25,26,27,28,29,30],"Dates of birth","Email addresses","Names","Passwords","Phone numbers","Physical addresses","Purchases","Salutations","\u003Cp>The T2 data breach is a customer data incident from April 2024 associated with Australia-based specialty tea retailer T2. The record includes 94,584 unique email addresses. Data classes include dates of birth, email addresses, names, passwords hashed with scrypt, phone numbers, physical addresses, purchase information, and salutations. The combination of retail and password fields makes this record high priority.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>In this record, contact information, purchase context, and password field appear together. Email, name, phone, and address create the user's customer profile; purchase information makes fake orders, returns, shipping, and campaign messages more convincing. The hashed password, on the other hand, paves the way for account takeover attempts if the same password is used on other accounts.\u003C\u002Fp>\u003Cp>When fields such as name, email, phone, address, username, or location come together, attackers may approach the user as if there is a legitimate service relationship. This information alone does not always mean account takeover; however, it can be used for phishing, fake support requests, account verification, and personalized fraud flows. The record does not list full payment card data. Although some secondary reports mention payment methods or partial payment details, the main data classes for this record are purchase history and passwords hashed with scrypt. It should not be said that the user's plaintext password was leaked, but urgent action should be recommended against password reuse.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The incident date is recorded as April 17, 2024, and the number of affected emails is 94,584. Reliable breach records indicate that around 95,000 T2 records were shared, including fields such as email, physical address, name, phone number, date of birth, purchase information, and password hashed with scrypt. The existing data classes are consistent with this scope.\u003C\u002Fp>\u003Cp>While explaining the scope, it should not be assumed that all fields are present in every line. The incident should not be generalized like a payment card leakage; it should remain focused on customer communication, purchase history, and password security. Accounts using the same password outside of the T2 account should also be included in the risk assessment.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Users at risk are those who have opened an account at the T2 store, placed an online order, or shared delivery information. Users accustomed to loyalty, campaign, and shipping messages may respond to fake links more quickly.\u003C\u002Fp>\u003Cp>People who use the same password for email, shopping, or payment accounts carry a higher risk. Birth date and salutation fields can personalize messages. If phone and address information is up to date, the likelihood of being targeted via SMS and calls also increases.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Matched users should change the password on their T2 account and separate all accounts that use the same password. Shipping, return, payment correction, or campaign messages should be verified through the official website or application.\u003C\u002Fp>\u003Cp>Instead of opening incoming links directly, the user should log in through the known web address or official application of the relevant service. Knowing the caller's name, email, address, order, or profile information does not prove that they are trustworthy. One-time verification codes, payment card information, or account passwords should not be shared in any support conversation.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, the habit of using a password manager, unique passwords, two-factor authentication, and removing unnecessary personal information from accounts reduces risk. Reusing the same email address across different platforms makes it easier to combine data from different breaches; using a separate email or alias for critical accounts can be considered.\u003C\u002Fp>\u003Cp>Old delivery addresses, unnecessary phone numbers, and unused payment\u002Fmembership information should be regularly cleaned in retail accounts. In breaches involving passwords, a permanent solution is to use unique passwords for all shopping accounts.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>LeakData check indicates whether the queried email address is present in this record. A positive result does not necessarily mean that all data fields definitely belong to that user; however, it is a sufficient warning for precautionary measures. A negative result only indicates that there is no match in this dataset and does not eliminate the possibility of appearing in other breaches.\u003C\u002Fp>\u003Cp>A positive result increases the T2 account and purchase-related social engineering risk. A negative result means there is no match within this record; the same email should also be checked in other retail records.\u003C\u002Fp>","T2 Data Breach (94.6 Thousand Reported Records)","T2 Data Breach. 94.6 Thousand reported records were reported. Reported data: Dates of birth, Email addresses, Names. Review the scope, risks, and protective…","\u002Fuploads\u002Flogo\u002Ft2tea_com.webp",false,{"name":37,"sector":38,"country":39,"website":9,"websiteArchiveUrl":15,"websiteStatus":15,"websiteCheckedAt":19},"T2","Retail \u002F Tea Store","Australia"]