Alibaba's Lazada Suffers Data Breach Involving 1.1M Users

The data breach reportedly occurred on a third-party server, used exclusively to store RedMart's user information. None of Lazada’s users are said to be affected.

What Happened: The breach on Thursday exposed email addresses, telephone numbers, encrypted passwords, and partial credit card numbers, according to Channel News Asia, which first reported the news.

Lazada confirmed to CNBC that personal data was stolen but claimed the information affected was "more than 18 months out of date." RedMart platform was decommissioned in March 2019.

The Alibaba-owned company said access to the stolen database has been blocked. Reportedly, affected users were signed out of their accounts, and were asked to reset passwords.

Singapore’s regulatory watchdog, the Personal Data Protection Commission is investigating the incident and local police have been notified.

Despite claims that the company does not store credit card numbers and CVV details, Lazada told users to track any “unusual activity or suspicious transactions on your credit cards,” ZDNet noted earlier.

Alibaba gained a controlling interest in Lazada in April 2016 for $1 billion. Six months later, in November, Lazada purchased RedMart for an undisclosed amount estimated between $30 million to $40 million.

Price Action: BABA stock dropped 2.52% on Friday to close at $304.69 per share.

Market News and Data brought to you by Benzinga APIs

To add Benzinga News as your preferred source on Google, click here.