Groupe Afflelou
Incident posture
Linked entities
- Victim
- Groupe Afflelou
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
A French eyewear retailer disclosed a cybersecurity incident caused by a vulnerability in a third-party service provider's system, which allowed unauthorized access to the company's customer relationship management platform. The exposed personal data included names, dates of birth, postal and email addresses, phone numbers, purchase histories and quotes, health insurance provider names, appointment dates, store affiliations, and parental status information. The company confirmed that no banking details, social security numbers, vision or hearing correction data, or passwords were compromised in the breach. An investigation was initiated alongside a notification to the French data protection authority, and the company stated it had implemented measures to prevent recurrence while remaining unaware of any fraudulent use of the stolen information.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On April 1, 2025, it was reported that Alain Afflelou, the French eyewear and hearing aid retail chain, had fallen victim to a cybersecurity incident. The company informed its customers of the event through an email, which was obtained by the French technology outlet Tech&Co. In that communication, the company stated that it had been "confronted with a cybersecurity incident." The root cause of the breach was identified as a vulnerability in a system operated by one of the group's service providers. This flaw enabled an unauthorized third party to gain access to the French company's customer relationship management (CRM) tool, which is used to store and process client information. Following the discovery of the intrusion, the company initiated a notification process to alert its clientele and also filed an official report with the French data protection authority, the Commission Nationale de l'Informatique et des Libertés (CNIL), as required under French data protection regulations.
The data exposed in the breach, while personally identifying, was largely categorized as non-sensitive in the context of typical data protection standards. The compromised CRM database contained a wide array of client information, including full names, dates of birth, postal addresses, email addresses, and telephone numbers. Additionally, commercial details such as records of recent purchases and quotes, the name of the client's health insurance provider (mutuelle), the date of their last appointment, and the specific Afflelou store to which the customer was linked were accessed. The customer's parental status was also among the leaked information. Crucially, the company emphasized that no highly sensitive financial or identification data was included in the compromised dataset. Specifically, no bank card numbers, no social security numbers, no visual or auditory correction prescriptions, and no passwords were part of the breach. At the time of the initial reporting, the total number of customers affected by this data leak had not been disclosed. Alain Afflelou, which has been operating in the teleconsultation sector since 2022, confirmed that the breach was confined to the CRM data.
In response to the incident, the company asserted that it had implemented the necessary measures to prevent any recurrence of the breach. Furthermore, as of the date of the article, the company stated it had no evidence that the stolen data had been used for fraudulent purposes. The internal investigation to fully understand the sequence of events that led to the unauthorized access was ongoing at the time of reporting. Although no fraud had been observed, security experts noted that the specific nature of the leaked data could potentially facilitate targeted phishing campaigns related to optical and hearing care services in the future. Customers were advised to remain vigilant and to contact Afflelou's customer service directly in the event of any uncertainty. Despite multiple attempts by Tech&Co to obtain further comment, Alain Afflelou had not responded to requests for additional information by the time the article was published.
Sources
Sources available to members: 1 source.