TechNewsReel
Live

Singapore Retailer Love, Bonito Warns of Scam Risks After Data Breach

The fashion brand notified customers of exposed personal and partial payment data following a website security vulnerability.

TechNewsReel Newsroom · August 1, 2026

Singaporean fashion retailer Love, Bonito has alerted its customers to an increased risk of phishing and scams following a data breach. The company identified a security vulnerability on its website, which was resolved on Sunday, July 26.

The breach potentially exposed a wide array of personally identifiable information, including customer names, dates of birth, email addresses, phone numbers, shipping addresses, and order histories. According to the company, partial payment details—specifically card types, expiry dates, and the last four digits of cards—may have also been affected. Full credit card details remained secure because they are managed by a third-party payment processor; the company does not store this sensitive financial information directly.

A Pattern of Vulnerability

This incident is not the first security failure for the prominent retailer. Love, Bonito was fined S$24,000 in 2024 for a separate data breach that occurred in 2019, which affected more than 5,500 customers. That previous incident involved malicious code that led to the exfiltration of customer data, resulting in regulatory action from the Personal Data Protection Commission (PDPC).

Industry Implications

The recurrence of breaches at a major e-commerce platform underscores the persistent cybersecurity challenges facing digital retail. The combination of exposed personal data and partial financial fragments creates a high-risk environment for targeted social engineering. Attackers can use leaked order histories and contact details to craft highly convincing phishing messages, making it easier to deceive customers into revealing further sensitive information.

Next Steps

Love, Bonito has reported the current incident to law enforcement, including the Singapore Police Force, and has notified the PDPC. The company stated it is continuing to audit and review its security measures to prevent future occurrences. Customers are advised to remain vigilant against unsolicited communications and monitor their accounts for suspicious activity.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.