DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Ouidad notifies customers after customer data viewed or obtained

Posted on October 18, 2013 by Dissent

Hair care product manufacturer and e-tailer Ouidad is notifying customers that they were recently alerted to a compromise of their customer database that occurred between June 30 and July 4.

In a letter to those affected, they write:

 It appears the attackers obtained or viewed information about one or more transactions you completed at Ouidad.com including your first and last name, credit card number, credit card security code and expiration date, billing address, email address, [user name, password,] and phone number.

Ouidad reset passwords for those whose passwords were involved, and has offered those affected a free one-year membership in the Equifax Credit Watch Gold with Web Detect identity theft protection monitoring program.

According to their submission to the California Attorney General’s Office, they learned of the breach on September 20, but they do not indicate in their letter who alerted them to the problem and whether the initial alert was a report of credit card fraud. In fact, their letter is totally silent on the question of whether they are aware of any fraudulent use of customer information.

Update: 559 residents of New Hampshire were also notified of this breach.

Category: Business SectorHackU.S.

Post navigation

← French Data Protection Authority CNIL Announces New Online Notification Procedure For Reporting Data Breaches
Privacy breach at Northern Inyo Hospital could result in criminal charges →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Ex-NSA bad-guy hunter listened to Scattered Spider’s fake help-desk calls: ‘Those guys are good’
  • Former Sussex Police officer facing trial for rape charged with 18 further offences relating to computer misuse
  • Beach mansion, Benz and Bitcoin worth $4.5m seized from League of Legends hacker Shane Stephen Duffy
  • Fresno County fell victim to $1.6M phishing scam in 2020. One suspected has been arrested, another has been indicted.
  • Ransomware Attack on ADP Partner Exposes Broadcom Employee Data
  • Anne Arundel ransomware attack compromised confidential health data, county says
  • Australian national known as “DR32” sentenced in U.S. federal court
  • Alabama Man Sentenced to 14 Months in Connection with Securities and Exchange Commission X Hack that Spiked Bitcoin Prices
  • Japan enacts new Active Cyberdefense Law allowing for offensive cyber operations
  • Breachforums Boss “Pompompurin” to Pay $700k in Healthcare Breach

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Drugmaker Regeneron to acquire 23andMe out of bankruptcy
  • Massachusetts Senate Committee Approves Robust Comprehensive Privacy Law
  • Montana Becomes First State to Close the Law Enforcement Data Broker Loophole
  • Privacy enforcement under Andrew Ferguson’s FTC
  • “We would be less confidential than Google” – Proton threatens to quit Switzerland over new surveillance law
  • CFPB Quietly Kills Rule to Shield Americans From Data Brokers
  • South Korea fines Temu for data protection violations

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.