HauteLook Data Breach
HauteLook Flash Sale Fashion Platform Breach (2018): 28 Million User Records Including Passwords, DOB & Location Exposed
Online flash sale retailer.
Risk Interpretation
Exposure enables phishing, order fraud, and affluent-customer targeting. Time-sensitive retail context can also make impersonation scams feel more legitimate.
Impact & Downstream Threats
In mid-2018 HauteLook was among a group of e-commerce platforms whose data was compromised in a wave of breaches sold together on dark web marketplaces in early 2019. The exposed dataset for approximately 28.5 million accounts included email addresses, names, genders, geographic locations, dates of birth, and passwords. HauteLook notified users and initiated password resets. No settlement or significant regulatory action specific to this breach has been prominently documented. As the breach was
- Credential stuffing against reused passwords across other platforms
- Identity verification bypass using name + date of birth combination
- Targeted phishing campaigns using exposed email addresses
- Doxxing risk from physical address exposure
Threat Vectors
Breach Intelligence
Executive Summary
HauteLook, a flash sale fashion retailer operating under Nordstrom, suffered a data breach in mid-2018 that exposed records for approximately 28.5 million customer accounts. The breach was part of a wave of attacks targeting multiple e-commerce platforms around the same period. The stolen data was subsequently sold on dark web marketplaces in early 2019. The exposed information included email addresses, names, genders, dates of birth, geographic locations, and passwords. The passwords were stored as bcrypt hashes, a form of encryption that slows down cracking attempts but does not make them impossible. The combination of birthdate, location, and login credentials creates meaningful risk for affected customers, enabling phishing attacks, account takeover attempts, and impersonation scams. HauteLook's flash sale format, which creates urgency around time-limited offers, makes fake order or account alerts easier to make convincing. Nordstrom, as HauteLook's parent company, handled customer notifications and initiated password resets following disclosure of the breach. No prominent regulatory action or legal settlement specific to this incident has been publicly documented. Affected individuals should treat any email claiming to be from HauteLook or Nordstrom Rack with caution, particularly messages requesting login or payment details, and should update passwords on any other accounts where the same credentials were reused.
About HauteLook
HauteLook is an online flash sale retailer offering limited-time deals on fashion, beauty, and home goods from designer brands. It was acquired by Nordstrom in 2011 and now operates as part of Nordstrom's off-price digital commerce offering alongside Nordstrom Rack. The flash sale model positions limited inventory at discounted prices within short time windows to drive urgency-based purchasing.
Why They Hold Your Data
Flash-sale marketplaces collect customer identity, addresses, order history, payment-adjacent records, account activity, and brand-preference data tied to limited-time retail offers.
Recent Developments
HauteLook has continued operating within the Nordstrom portfolio. Nordstrom has been investing in its Rack and off-price channels as growth areas while managing its full-price store footprint. No major standalone HauteLook developments beyond the Nordstrom parent context have been prominently reported.
Data Points Exposed
Exposure Categories
Canonical Fields
date_of_birth, email_address, full_name, gender, geographic_locations, password
Dark Web Verification
- Dataset containing ~28.5M records identified in breach intelligence sources
- Data indexed and searchable across breach notification platforms
- Source: hautelook.com-2018;HauteLook Data Breach
Recommended Actions
⚠️ Do not assume this is low sensitivity.
Protect Yourself
Check If You’re Affected
Enter your email to check if your data appears in this breach.
Get Free Breach Alerts
Be the first to know when new breaches are disclosed.
High-Risk? Get an Exposure Audit
Full-spectrum exposure audits for executives and public figures.
ObscureIQ Advisory
We combine proprietary dark web access with commercial and restricted breach intelligence to verify exposure and assess real-world risk.
- A public-facing individual
- A high-profile executive
- A customer of HauteLook
- Or concerned about credential reuse
Powered by the ObscureIQ Breach Intelligence Database
© 2026 ObscureIQ · All Rights Reserved · Data Licensing
Latest from ObscureIQ
What Is Credit Monitoring? And Do I Want It? (Answer: Not Really)
Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars.
Sextortion Spam
