Love, Bonito website experienced 'security vulnerability', some customers' personal info possibly exposed
In 2024, Love, Bonito was fined S$24,000 over a 2019 breach.
Photo from Love Bonito/Google Maps.
The website of home-grown fashion brand Love, Bonito was compromised on Jul. 26, potentially exposing the personal information of some of its customers.
Partial payment information may have been exposed
In an email sent to affected customers, as seen by Mothership, the company said it had identified a security vulnerability on its website that allowed unauthorised access to some customers’ account information.
Love, Bonito said it acted "immediately" after discovering the issue and resolved the vulnerability on the same day.
"We have since strengthened our internal safeguards to prevent a similar issue from recurring," the company said.
"We have always been committed to providing our community with a safe shopping environment and we sincerely apologise for this incident."
According to the email, the following categories of one's personal information may have been affected:
- First and last name;
- Date of birth;
- Email address;
- Shipping address;
- Phone number;
- Order history details; and
- Partial payment information, including card type, the last four digits of the card and expiry date, if the card had been used for an order on Love, Bonito’s website.
The company stressed that customers’ full credit card details were not exposed.
"This information is processed and held directly by our payment processor — we do not have access to or store this information ourselves," it said.
Love, Bonito said it had also taken steps to secure and strengthen the affected systems, notified the relevant data protection authority and reported the incident to law enforcement.
The company added that it is continuing to audit and review its security measures and will make further improvements where necessary.
Urged customers to be mindful of scams
Meanwhile, Love, Bonito encouraged affected customers to be wary of phishing attempts and to remain vigilant about unexpected calls, e-mails or text messages that reference their names, addresses or order history.
Customers should not share one-time passwords or verification codes with anyone, including people claiming to represent Love, Bonito or their bank, the company said.
It also advised customers to monitor their payment card activity and register with the Do Not Call Registry to reduce unsolicited telemarketing calls and messages.
All affected customers have been informed
In response to Mothership's queries, Love, Bonito chief executive Dione Song said the company is taking the incident very seriously.
All affected customers in Singapore have been informed, she said.
"We sincerely apologise to our customers and are committed to strengthening our systems and are taking additional steps to enhance our cybersecurity," said Song.
The company has also notified the Singapore Police Force, the Personal Data Protection Commission (PDPC) and the relevant regional authorities, and is cooperating fully with their investigations.
Song added that they will not be able to share additional information at this point as the incident is currently under investigation.
Not the first time
This is not the first time Love, Bonito has experienced a data breach.
In 2019, the brand’s website was compromised, with about 3 per cent of its customers’ personal information exposed. Of these, a "small number" may have had their financial data accessed.
According to The Straits Times, in 2024, Love, Bonito was fined S$24,000 over the breach, which involved more than 5,500 customers.
MORE STORIES


















