In an email to customers on Thursday, CEO Dione Song said the company identified the vulnerability on Sunday and resolved it on the same day.
Based on its investigations, the data that may have been affected includes customers’ names, dates of birth, email addresses, shipping addresses, phone numbers and order history details.
Partial payment information – such as card type, the last four digits of card numbers and expiry dates – may also have been affected for customers who used cards on the website.
However, full credit card details were not exposed, the company said. “This information is processed and held directly by our payment processor – we do not have access to or store this information ourselves,” Song added.
Following the incident, Love, Bonito said it had secured the affected systems, notified the relevant data protection authority and reported the matter to law enforcement. It is continuing to review its security measures.

