Fashion Retailer Love, Bonito Reports Potential Customer Data Exposure
Translated from English, summarized and contextualized by DistantNews.
At a glance
- Fashion retailer Love, Bonito reported a security incident that may have exposed some customer data.
- The vulnerability, identified and resolved on July 26, could have exposed names, birth dates, email addresses, shipping addresses, phone numbers, and order history.
- Partial payment information, like card type and expiry dates, may also have been affected, but full credit card details were not compromised.
Singaporean fashion retailer Love, Bonito has alerted customers to a potential data breach following a security vulnerability on its website. The company stated that unauthorized access to account information may have exposed personal data of some customers.
In an email to customers on Thursday, July 30, CEO Dione Song explained that the vulnerability was identified and fixed on July 26. Investigations indicate that affected data could include customers' names, dates of birth, email addresses, shipping addresses, phone numbers, and details of their order history. For customers who used payment cards on the website, partial payment information, such as card type, the last four digits of card numbers, and expiry dates, might have also been compromised. Love, Bonito emphasized that full credit card details were not exposed, as this information is handled directly by their payment processor.
This information is processed and held directly by our payment processor - we do not have access to or store this information ourselves.
Following the incident, Love, Bonito has secured the affected systems, notified the relevant data protection authority, and reported the matter to law enforcement. The company is continuing to review its security measures and has strengthened internal safeguards to prevent recurrence. Customers are advised to remain vigilant against potential phishing attempts and to monitor their payment card activity for any unauthorized transactions. They are also encouraged to enable two-factor authentication and register their numbers with Singapore's Do Not Call Registry.
This incident follows a previous fine of S$24,000 (US$18,700) in 2022, when over 5,000 customers' personal data was accessed and stolen via malicious code on the company's e-commerce website. The Personal Data Protection Commission is currently investigating the latest incident.
We are continuing to audit and review our security measures, and will make further improvements as needed to prevent an incident of this nature from happening again.
Originally published by CNA in English. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.