Love, Bonito Under Regulatory Probe After Customer Data Breach
Singapore's PDPC and CSA are investigating the fashion retailer after a website vulnerability exposed personal and partial payment data.
Fashion retailer Love, Bonito has disclosed a security vulnerability on its website that allowed unauthorized access to customer account information. The incident has triggered investigations from Singapore's top data and security regulators, marking a recurring cybersecurity struggle for the home-grown brand.
The company identified the vulnerability on July 26, 2026, and resolved the flaw that same day. Despite the rapid fix, the window of exposure potentially compromised sensitive customer details. According to company disclosures, exposed data may include first and last names, birthdates, email addresses, shipping addresses, and phone numbers.
Financial data was also partially impacted. For customers who used a card on the website, partial payment information—specifically the expiry date and the last four digits of the card—may have been affected. Love, Bonito clarified that full credit card details were not exposed, as that information is managed by a third-party payment processor. Affected customers were notified of the breach on July 30, 2026.
A Pattern of Vulnerability
This is not the first time the retailer has dealt with the fallout of a data leak. In 2024, the Personal Data Protection Commission (PDPC) fined Love, Bonito $24,000 in relation to a separate 2019 breach. That earlier incident affected more than 5,500 customers, representing approximately 3% of the company's customer base at the time.
The recurrence of these vulnerabilities suggests a persistent struggle to secure its e-commerce infrastructure. CEO Dione Song issued an apology to customers, stating the company is "committed to strengthening our systems and are taking additional steps to enhance our cybersecurity."
Regulatory and Industry Implications
Because of the company's prior history, this latest incident is likely to draw significant regulatory heat. The PDPC and the Cyber Security Agency of Singapore (CSA) are currently investigating the breach. Given the previous $24,000 fine, the PDPC may view this as a systemic failure in data governance, which could lead to more severe penalties or mandatory audits.
For the broader e-commerce sector, the breach underscores the critical risk associated with website vulnerabilities and the necessity of robust encryption and access controls. As consumers become more sensitive to data privacy, repeated failures can erode brand trust more quickly than a single isolated event.
What's Next
Love, Bonito has notified the Singapore Police Force, the PDPC, and other regional authorities. The company is now awaiting the results of the official investigations by the CSA and PDPC. It remains to be seen whether the investigation will uncover a targeted attack or a systemic oversight in the website's code, and whether further customers will be identified as affected.