Data breach
Bonobos
- Records
- 15,843,782
- Breach date
- 14 August 2020Estimated
- Added
- 1 December 2024
What was exposed
1 type of data · 6 more reported
- Email addresses15,843,782
- PasswordsReported, not counted
- NamesReported, not counted
- Home addressesReported, not counted
- Phone numbersReported, not counted
- Purchase historyReported, not counted
- IP addressesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In August 2020, the men's clothing retailer Bonobos suffered a data breach after attackers gained access to a backup of the company's cloud-stored customer database. According to a court ruling in the resulting litigation, a hacking group known as ShinyHunters accessed the backup and stole personal information belonging to some or all of Bonobos' roughly seven million online customers. The stolen data later surfaced publicly, and the investigation team now indexes 15,843,782 records connected to this incident. No ransom demand or claiming actor is associated with the listing in our catalog.
Breach Timeline
August 14, 2020: Estimated date of the breach, when attackers accessed Bonobos' cloud backup database, according to Mozilla Monitor and our investigation team's records.
January 22, 2021: The stolen customer data was reported to be available for free on a hacker forum after a cybercriminal downloaded the company's backup cloud data, according to the University of North Alabama's security incident tracker.
January 2021: Bonobos sent breach notification emails to affected customers, telling them that an unauthorized third party may have been able to view contact information and an encrypted password, and that the company was resetting passwords and logging users out of their accounts, according to the court record in Cooper v. Bonobos Inc.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses.
Reporting and court records tied to the incident indicate the underlying stolen database also contained customer names, physical addresses, phone numbers, order and purchase histories, IP addresses, passwords stored in encrypted (hashed) form including historical passwords, and partial credit card details such as card type, the name on the card, expiry date, and the last four digits of the card number.
Bonobos' notification to customers stated that encrypted passwords were protected so that actual passwords were not visible and that payment card information was not affected. Security researchers and breach trackers, however, have reported that partial card data was present in the stolen dataset. The exact number of unique email addresses in the indexed records is unknown.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The exposure of names, home addresses, phone numbers, and order histories creates a meaningful risk of targeted phishing and smishing attacks. Scammers can use real purchase details to impersonate retailers, delivery companies, or banks convincingly, referencing legitimate orders to trick recipients into handing over payment details or login credentials.
Although passwords were encrypted, attackers routinely attempt to crack stolen hashes and test the results against other websites. Customers who reused their Bonobos password elsewhere face a risk of account takeover. In the Cooper v. Bonobos litigation, a federal court ultimately found the risk of identity theft from this data too remote to support standing in that particular case, but the phishing risk from contact and purchase data remains real for individuals.
What Is Bonobos Doing in Response?
In January 2021, after the data appeared on a hacker forum, Bonobos notified affected customers and reset account passwords, logging users out of their accounts. The company's notice stated that its encrypted password storage prevented actual passwords from being visible and that payment card information was not affected. We did not find records of a broader public remediation program, such as credit monitoring, in the sources reviewed as of September 25, 2026.
What Should You Do If You Were Affected?
Change your Bonobos password if you have not already, and change it anywhere you reused the same password.
Enable two-factor authentication on your email, shopping, and financial accounts.
Be skeptical of unexpected emails, texts, or calls that reference orders, deliveries, or your account. Verify directly through the company's official website rather than links in a message.
Review statements for payment cards you used at Bonobos and report any unfamiliar charges to your bank.
Watch for phishing attempts that use your name, address, or order history to appear legitimate.
