Singapore-founded fashion retailer Love, Bonito has confirmed its second data breach in under a decade, after a website vulnerability discovered on 26 July exposed customer names, dates of birth, email addresses, shipping addresses, phone numbers, order history and partial payment details. Full credit card information was not affected, as it is held separately by the retailer’s payment processor.
The company said it resolved the vulnerability on the same day it was identified and has since notified Singapore’s Personal Data Protection Commission (PDPC), which is investigating the incident. In 2024, Love, Bonito was fined S$24,000 over a 2019 breach that exposed the personal data of more than 5,500 customers.
A repeat breach shifts the question to vulnerability management
Takanori Nishiyama, Senior Vice President APAC and Country Manager, Japan at Keeper Security, said a second breach at the same retailer moves the conversation beyond misfortune.
“Closing the flaw the same day matters, but sustained security hygiene matters just as much. That begins with deliberate control over who and what can reach the systems behind the storefront,” said Takanori Nishiyama, Senior Vice President APAC and Country Manager, Japan, Keeper Security.
He noted that every online storefront concentrates customer names, addresses, order histories and payment details in one place, making e-commerce platforms an attractive target. Citing the Verizon 2026 Data Breach Investigations Report, Nishiyama pointed to regional figures underscoring the scale of the problem:
- External actors were behind 99 per cent of breaches recorded in APAC
- Vulnerability exploitation was the top access vector, accounting for 42 per cent of cases
- Love, Bonito’s 2019 breach exposed data belonging to more than 5,500 customers, resulting in a S$24,000 PDPC fine
Applying zero-trust principles to the storefront
Nishiyama argued that securing e-commerce platforms is a shared responsibility between platforms and merchants, who should enforce phishing-resistant multi-factor authentication and least-privilege access on administrative consoles, and rotate credentials and API keys regularly.
“The answer is to apply zero-trust principles across the entire storefront: verify each access request and grant only the privileges a task requires. Enforced consistently across human and non-human identities, this approach turns a single compromised credential from a breach into a non-event,” he said.
He added that while consumer logins increasingly support passkeys, privileged access to servers, databases and payment integrations often still relies on shared passwords and static API keys that never expire — a gap he described as one of the more overlooked risks in retail security architecture.

