
FullBeauty Brands 2025 Data Breach (4.7 Thousand People Affected)
The 2025 FullBeauty Brands data breach involved an unauthorized person accessing the company's internal computer network and acquiring copies of certain files. FullBeauty Brands says it detected the cybersecurity incident on October 22, 2025.
The U.S. Department of Health and Human Services Office for Civil Rights recorded the incident associated with the FullBeauty Brands employee benefits plan as a hacking/IT event involving a network server and reported 4,725 affected individuals.
Verified Incident TimelineThe company's investigation determined that an unauthorized person accessed the network between October 18 and November 19, 2025 and copied certain files. FullBeauty Brands determined on November 14, 2025 that some files contained employment-related information and began mailing notification letters on January 16, 2026.
What Information May Have Been Affected?The information varied by person but may have included first and last names, Social Security numbers, and health-plan enrollment information. The notice indicates that the data types were not the same for every person.
How the Organization RespondedFullBeauty Brands says it secured the network, investigated with cybersecurity partners, and implemented additional network-security measures. The organization also said it would increase employee awareness of cyber threats and offered notice recipients one year of credit monitoring and identity-theft protection.
What Should Affected People Do?Notice recipients should activate the offered protection service within the notice's deadline if eligible and review credit reports and health-plan records for changes they do not recognize. Incident-related links and contact details should be verified through the organization's official channels before use.