Dymocks blamed an external data partner for a breach of 836,000 customers
- Organization
- Dymocks
- Exploit
- Third-Party Data Breach
- Industry
- Retail
Dymocks, the Australian bookseller founded in 1879, told customers on September 8, 2023 that some of their personal information had been compromised and was circulating on the dark web.
The company said it became aware of the problem on September 6 after finding evidence of discussions about its customer records on criminal forums. Have I Been Pwned listed the leaked set as roughly 1.2 million records covering 836,120 unique email addresses. Reporting indicated that copies had been traded on Telegram channels and hacking forums since at least June 2023, and that the most recent account creation date in the data was June 20, 2023, suggesting the theft had occurred months earlier.
The exposed fields included names, dates of birth, email and postal addresses, mobile numbers, gender, and loyalty program details such as gold expiry dates, account status, account creation date and card ranking. Passwords, driver's licence numbers, transaction histories and payment card data were not included.
Managing director Mark Newman said Dymocks had found no evidence that its own systems were penetrated. Later in September the company said the compromise appeared to have occurred in the systems of an external data partner, which it did not name. Dymocks reported the matter to Australian authorities, advised customers to change their account passwords and watch for phishing, and said its online shop remained safe to use.