Another week, another major data breach. This time, 50 million records from a popular retail loyalty program were exposed — including names, email addresses, and hashed passwords.
What Was Exposed
The breach included full names, email addresses, phone numbers, and hashed passwords. While the passwords were hashed (scrambled), modern cracking tools can reverse weak hashes quickly. If you used a simple password, assume it's compromised.
No payment card data was exposed in this breach — the company stored that separately. But the combination of name, email, and phone number is enough for targeted phishing attacks.
The One Thing You Should Do Right Now
Change your password for that service immediately. Then check if you used the same password anywhere else — if you did, change those too. Use a password manager to generate unique passwords going forward.
Check haveibeenpwned.com to see if your email appears in known breaches. It's free, it's trustworthy, and it takes 30 seconds. Set up breach alerts so you're notified automatically in the future.
Key Takeaway
Visit haveibeenpwned.com, check your email, and change any reused passwords immediately. Set up breach alerts so you're never caught off guard again.
Deborah Edem
Cybersecurity Analyst · CyberHygienics