SINGAPORE, July 31 — Fashion retailer Love, Bonito said some customers’ personal data may have been exposed after a security vulnerability on its website allowed unauthorised access to account information.
The regional womenswear brand said it identified and fixed the vulnerability on July 26, and has since launched investigations into the incident, Singapore-based news outlet CNA reported today.
“We are continuing to audit and review our security measures, and will make further improvements as needed to prevent an incident of this nature from happening again,” chief executive officer Dione Song was quoted as saying in an email to customers.
The Singapore-founded company said the potentially affected information includes customers’ names, dates of birth, email addresses, shipping addresses, phone numbers and order history details.
Partial payment information, including card type, the last four digits of card numbers and expiry dates, may also have been exposed for customers who used cards on its website.
However, Love, Bonito said full credit card details were not affected.
“This information is processed and held directly by our payment processor — we do not have access to or store this information ourselves,” Song was quoted as saying.
The company said it had secured the affected systems, notified the relevant data protection authority and reported the matter to law enforcement.
Love, Bonito also advised customers to stay alert for possible phishing scams, warning that exposed personal details could be used to make fraudulent messages appear more convincing.
Customers were urged not to share one-time passwords or verification codes, and to monitor their payment card activity for suspicious transactions.
Singapore’s Personal Data Protection Commission is investigating the incident, while Love, Bonito said it is continuing to review its security measures.
Love, Bonito, which operates online and physical stores, including Malaysia, Indonesia, Hong Kong and Cambodia, was fined S$24,000 (RM75,120) in 2022 after more than 5,000 customers’ personal data was accessed and stolen through malicious code on its e-commerce website.