🔒breach.co.nz · the NZ & Australia breach register 🛡️ A Govern service
Register › 🇦🇺 AU › Retail
Retail sector · leaderboard
Own the Retail leaderboard
The top banner across the Retail overview and every Retail record — one advertiser, exclusively.
Own this leaderboard → breach@govern.co.nz

Dymocks

🇦🇺 Sydney, NSW · Dymocks Booksellers · Record AU-2023-0255
○ Reported — awaiting official confirmation
Reported — awaiting official confirmation. The facts below are drawn from the organisation's own disclosure and credible reporting. Figures are as reported; unknowns are labelled, not estimated by us.
People affected
836,000 (approx)
Breach date
2023-06
Regulator
OAIC (notified)
Trust tier
B · Reported

Data exposed

Names, dates of birth, email and postal addresses, membership details Media-reported

Confidence: Confirmed = regulator/court · Company-confirmed = the organisation's own disclosure · Media-reported = press. Figures without an official source are labelled, not estimated.

What happened

In September 2023 Dymocks Booksellers disclosed a breach affecting around 836,000 customer records — names, dates of birth, email and postal addresses and membership details — after customer data appeared on the dark web [bleeping-dymocks]. The breach is understood to have originated with a third-party provider.

Timeline

  • 2023-06 — Unauthorised access believed to have occurred [bleeping-dymocks].
  • 2023-09 — Dymocks disclosed the breach; ~836,000 customers affected [bleeping-dymocks].

Current status

Disclosed; customers notified. A class-action investigation was reported. Figures are as reported. [bleeping-dymocks]

Why it matters

A large consumer-retail breach reached through a third party — the loyalty database, not the storefront, was the target.

GGOVERN Tabletop Exercises · Govern house Strengthen your cyber resilience — rehearse the decisions that matter. Book a Discovery Call →