Jinny Beauty Supply Data Breach Exposes Credit Card Numbers and Social Security Numbers

Published: 7 September 2026
Retail data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: September 2026

Jinny Beauty Supply, a major Korean-American beauty wholesale distributor, suffered a ransomware attack by the group aurora that exposed customer credit card data, employee Social Security numbers, bank account details, and extensive internal system credentials. The breach affects customers, employees, and business partners across dozens of US states. Anyone connected to the company should monitor their credit reports and consider a credit freeze immediately.

CompanyJinny Beauty Supply
IndustryRetail
Data Types ExposedCredit Card Numbers, Social Security Numbers, Bank Account and Routing Numbers, Dates of Birth, Employee Salary Data, Customer Names and Contact Information, Login Credentials
People AffectedNot Publicly Disclosed
Attack MethodRansomware
Regulators NotifiedNot Publicly Disclosed

What Happened in the Jinny Beauty Supply Data Breach?

Jinny Beauty Supply, one of the largest Korean-American wholesale beauty distributors in the country, has confirmed a serious cybersecurity incident. The company runs nine distribution centers across the US, stretching from Doraville, Georgia to Commerce, California. It supplies more than 7,400 beauty supply stores and over 2,800 international distributors, making it a major link in the beauty retail supply chain.

A ransomware group known as aurora claimed responsibility for the attack. According to available records, the group gained deep access to Jinny Beauty Supply’s internal systems, including its password vault, virtual infrastructure, and multiple internal databases. As a result, a huge volume of sensitive business and customer information was exposed.

The exact discovery date has not been publicly disclosed. However, notification of the incident occurred in September 2026. Because the exposed data spans systems dating back to 2015 and forward to 2020, the investigation likely required extensive forensic review to determine the full scope of compromised material.

Given the breadth of what was accessed, including administrator-level credentials and root access to virtualization systems, this appears to be a deeply penetrating intrusion. In addition, the presence of scanned credit card authorization forms suggests the attackers reached both operational and customer-facing systems. This points to a company-wide compromise rather than an isolated system failure.

Who was affected?

Multiple groups appear to be affected by this breach. This includes customers who submitted credit card authorization forms, current and former employees, and beauty supply store business partners whose data lived in company systems. Because Jinny Beauty Supply serves thousands of retail stores, the ripple effects could extend well beyond the company’s own staff.

The exact number of individuals affected has not been publicly disclosed. However, the scope suggests a substantial population. For example, the exposed employee compensation database includes roughly 260 employees, while the credit card authorization forms alone cover 911 documents. In addition, the Shopify customer database and SQL Server backups likely include thousands of additional customer records.

Because the company operates across 26 US states through its retail partners, the geographic reach of this breach is significant. Both domestic customers and international distributors could be impacted. It is also possible that data belonging to minors exists within family purchase records, though this has not been specifically confirmed.

What Information Was Potentially Exposed?

The scope of exposed data in this breach is unusually broad. It spans financial credentials, customer payment information, employee tax records, and deep technical access to company infrastructure. This combination makes the incident especially concerning for anyone connected to Jinny Beauty Supply.

  • Full credit card numbers, CVV codes, expiration dates, and cardholder signatures
  • Social Security numbers from employee W-4 and I-9 tax forms
  • Bank account and routing numbers from direct deposit forms
  • Employee dates of birth and citizenship status
  • Names, salaries, bonuses, and departmental data for company staff
  • Customer names, emails, phone numbers, and mailing addresses
  • Plaintext login credentials for PayPal, Amazon Seller Central, Microsoft 365, and other business platforms
  • Active Directory account data and encrypted remote desktop passwords

Because both financial and identity data were exposed together, the risk of harm is elevated. For instance, a criminal with a Social Security number, date of birth, and bank account details has nearly everything needed to open new credit lines. Similarly, exposed credit card numbers with CVV and signatures could enable direct fraudulent charges before a cardholder even notices.

Beyond financial fraud, this breach also raises concerns about corporate account takeover. Since the attackers reportedly obtained root credentials to virtual servers and dozens of admin accounts, they could potentially access even more systems in the future. As a result, both individuals and the business itself face ongoing exposure risk until all credentials are fully rotated and secured.

What is the company doing?

Jinny Beauty Supply has acknowledged the incident and is working to determine its full impact. In response, the company is likely conducting a thorough review of its network architecture, given that attackers reached systems across seven geographic sites. This kind of review typically includes resetting credentials, patching vulnerabilities, and isolating compromised servers.

Because the breach involves financial account numbers and Social Security numbers, affected individuals should expect formal notification letters describing what specific information was compromised. In addition, companies facing incidents of this scale often provide credit monitoring or identity protection services to affected consumers and employees. If such services are offered, individuals should enroll promptly to reduce their risk.

Moving forward, the company will likely continue strengthening its security posture. This may include multi-factor authentication rollouts, stricter access controls for administrator accounts, and closer monitoring of its e-commerce and ERP systems to prevent a repeat incident.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Anyone connected to Jinny Beauty Supply, whether as a customer or employee, should check their credit reports regularly. Because Social Security numbers and financial account details were exposed, new account fraud is a real possibility. You can request free credit reports from each of the three major bureaus.

Look closely for unfamiliar accounts, credit inquiries, or address changes. Because fraud can take months to surface, it helps to check reports periodically rather than just once. If you notice anything suspicious, dispute it immediately with the credit bureau involved.

Consider a Credit Freeze or Fraud Alert

Given that full Social Security numbers and bank routing numbers were part of this breach, a credit freeze offers strong protection. A freeze blocks new creditors from accessing your credit file, which stops most attempts to open accounts in your name. This step is free and can be lifted temporarily whenever you need to apply for credit yourself.

Alternatively, a fraud alert requires lenders to verify your identity before extending credit. This option is less restrictive than a freeze but still adds a layer of protection. Either way, acting quickly reduces the window criminals have to misuse your information.

Watch for Phishing and Scam Attempts

Because names, emails, and phone numbers were exposed, affected individuals should expect an increase in phishing attempts. Scammers often use breached data to craft convincing messages that appear to come from trusted companies. Therefore, treat unexpected emails or texts referencing Jinny Beauty Supply with caution.

Never click links or provide personal information in response to unsolicited messages. Instead, contact the company directly using a verified phone number or website. This simple habit can prevent a phishing attempt from turning into a real financial loss.

Protect Your Bank Accounts

Since direct deposit forms containing bank account and routing numbers were exposed, employees in particular should contact their banks. Many banks can flag an account for extra monitoring or issue new account numbers if needed. This proactive step can prevent unauthorized withdrawals or fraudulent transfers.

In addition, set up transaction alerts through your bank’s mobile app or website. These alerts notify you instantly of unusual activity, allowing you to respond before losses grow. Because this breach involved routing numbers specifically, this precaution is especially relevant for affected employees.

Consult a Data Breach Attorney

Given the scale and sensitivity of the data involved, affected individuals may want to speak with a data breach attorney. An attorney can help determine whether you qualify for compensation through a class action or individual claim. Many offer free case evaluations, so there is little downside to asking questions.

Because deadlines for filing claims can be strict, it helps to act sooner rather than later. A legal consultation can also clarify what documentation you should keep, such as notification letters or evidence of fraud, in case you decide to pursue a claim later.



Related Data Breaches

See the latest data breaches we're tracking →