Love, Bonito customers’ personal information possibly exposed in data breach

AI generated

SINGAPORE – The personal data of some customers of home-grown fashion label Love, Bonito may have been compromised in a recent data security incident.

In an e-mail sent to affected customers on July 30 and seen by The Straits Times, the company said it identified a “security vulnerability” in its website on July 26 that allowed unauthorised access to some customers’ account information.

The e-mail did not state how many people were affected or what the vulnerability was.

The brand said: “Upon discovering this issue, we acted immediately to contain it. The vulnerability was resolved on the same day it was identified, and we have since strengthened our internal safeguards to prevent a similar issue from recurring.”

Information that could have been exposed includes customers’ first and last names, birth dates, e-mail addresses, shipping addresses and phone numbers.

Payment information, such as the card’s last four digits and expiry date, may also have been affected if customers had used a card for an order on the Love, Bonito website, according to the e-mail.

Love, Bonito stressed that the full credit card details of customers were not exposed.

It said: “This information is processed and held directly by our payment processor – we do not have access to or store this information ourselves.”

The company added that it has notified the relevant data protection authority and reported the matter to law enforcement.

“We are continuing to audit and review our security measures, and will make further improvements as needed to prevent an incident of this nature from happening again,” said Love, Bonito.

Meanwhile, it encouraged customers to be wary of phishing attempts and stay alert to unexpected calls, e-mails or text messages referencing their names, addresses or order history.

One-time passwords or verification codes should not be shared with anyone, including individuals claiming to be from Love, Bonito or the customers’ bank.

Customers should also monitor their payment card activity and register with the Do Not Call Registry to reduce unsolicited telemarketing calls and messages.

In 2024, Love, Bonito was fined $24,000 over a 2019 data breach involving more than 5,500 customers.

The Straits Times has contacted Love, Bonito, the Cyber Security Agency of Singapore and the Personal Data Protection Commission for more information.