[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fjgt8q9m5gu0g":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":11,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":16,"affectedCount":16,"affectedCountStatus":17,"affectedCountLowerBound":18,"affectedCountUnit":19,"hasEnglishDescription":4,"severity":20,"dataClasses":21,"description":26,"seoTitle":14,"seoTitleEn":27,"seoDescription":14,"seoDescriptionEn":28,"logoUrl":29,"isVerified":4,"isSensitive":4,"isSpamList":30,"isMalware":30,"company":31},"68e3266eda11adda48825429","young-living-essential-oils","Young Living Essential Oils Data Breach","youngliving.com","2024-12-11T00:00:00.000Z","2024-12-19T14:37:40.000Z","2026-07-19T00:01:41.089Z","Third party breach","",[],1128951,"known",null,"unknown","Critical",[22,23,24,25],"Dates of birth","Email addresses","Geographic locations","Names","\u003Cp>The Young Living Essential Oils data breach is a security incident recorded in the December 2024 period that affected approximately 1.13 million accounts. The data set associated with the wellness and multi-level marketing company included fields such as username, email, country, and date of birth. This statement has been prepared to clarify which of the user's data may be at risk and what steps they should take first.\u003C\u002Fp>\u003Cp>When combined with date of birth and country information in the context of health-wellness and sales network, it increases personal profile risk. The text only uses data classes that can be verified; unverifiable password, payment, identity, or technical claims are not added as data fields. Events with similar names and different years of the same brand are not confused with each other.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data listed in this incident are as follows: dates of birth, email addresses, geographic locations, and names. The date of birth and country field can be used for targeted messages in the context of membership or sales networks. The presence of these fields together may facilitate attackers in preparing fake account reports, fraud, identity correlation, or targeted social engineering attempts.\u003C\u002Fp>\u003Cp>In this record, the password field is not listed; the risk arises from the presence of identity and demographic fields together. If there is no password, the risk does not completely disappear; address, phone number, date of birth, device information, work profile, loyalty program, web activity, or purchase information can also be sufficient to target the user. If there is a password, it should be urgently checked whether the same password has been reused on other services.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The breach encompasses approximately 1.13 million unique email addresses associated with the domain youngliving.com. The incident falls within the verified breach category. The scope was determined by comparing the domain, company context, country, industry, account count, and data classes. The fields displayed to the user are limited to those listed within the breach.\u003C\u002Fp>\u003Cp>Since the company's response is limited, the explanation has been kept confined to data fields without adding technical details that have not been finalized. In some cases, company verification may be limited or the dataset may have been distributed in third-party environments. In this case, the explanation focuses on the fields that show the user's real risk, without enlarging the points that are not certain.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Young Living members, individuals with a customer or independent seller account, and users whose date of birth information has been exposed are at risk. The main risk for these users is that the leaked fields are matched with common information used on other platforms. If the same email, phone number, username, address, social profile, or password is repeated across different accounts, the attack surface increases.\u003C\u002Fp>\u003Cp>Wellness and sales network context can be used in fake membership, order, commission, campaign, or account verification messages. Gaming, retail, payment, social profile, travel, investment, airline, and health-wellness contexts produce different risks. The user should consider not only the list of domains but also which account or service those domains are associated with.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users should check their email security and verify membership and order messages through the official channel. If a password or password-like field is listed, users should change it on all accounts where they use the same or similar password, use a unique password, and enable multi-factor authentication where possible. The email account should also be protected.\u003C\u002Fp>\u003Cp>If there are fields such as address, phone number, date of birth, device, business profile, purchase or loyalty program, users should check account recovery options, session history, forwarding rules, and suspicious messages. Verification and document requests received in the context of finance, payment, or airlines should be confirmed through a second channel.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Unnecessary sharing of birth date or country information in wellness and sales network accounts should be reduced. In the long term, a password manager, unique password, multi-factor authentication, closing old accounts, and deleting unnecessary profile fields are the fundamental defense. Since permanent personal data cannot be retrieved, user behavior and account settings should be reinforced.\u003C\u002Fp>\u003Cp>Data minimization for institutions, the retention period of old customer records, forum and community account permissions, loyalty program fields, and incident reporting processes should be regularly audited. On the user side, not using the same identity information everywhere permanently reduces risk.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>If the user matches this record, they should check the wellness, shopping, and sales network accounts they use with the same email. If a match is found, the user should read which data fields are listed and determine the order of actions accordingly. If there is a password, changing the password is a priority; if there is an address or phone number, a fraud alert is a priority; if there is finance or payment information, account monitoring is a priority; if there is a social profile, privacy control is a priority.\u003C\u002Fp>\u003Cp>Final assessment: Although this record does not contain a password, it is a sensitive personal data incident due to the birth date and location fields. The user should compare this record with their account history; they should check the services where they have used the same email, phone number, username, address, or password separately. Suspicious calls, emails, messages, or account recovery notifications should be considered higher risk after the incident.\u003C\u002Fp>","Young Living Essential Oils Data Breach (1.1 Million Reported Records)","Young Living Essential Oils Data Breach. 1.1 Million reported records were reported. Reported data: Dates of birth, Email addresses, Geographic locations…","\u002Fuploads\u002Flogo\u002Fyoungliving_com.webp",false,{"name":32,"sector":33,"country":34,"website":9,"websiteArchiveUrl":14,"websiteStatus":14,"websiteCheckedAt":18},"Young Living Essential Oils","Multi-level Marketing \u002F Wellness Retail","United States"]