Cyber Incident Victim: Avon
Date:
Jun 2020
Location:
United Kingdom
Summary
Avon experienced a cyber-security incident disrupting its IT infrastructure, partially affecting operations and interrupting systems across multiple markets including the UK, Argentina, Brazil, Poland, and Romania. Distributors reported backend access issues preventing order processing, with some systems restored in Poland and Romania during recovery efforts. The company filed disclosures confirming an investigation into potential user data compromise but asserted no financial data was involved due to its ecommerce platform’s storage practices. While sources attributed the attack to the DopplePaymer ransomware gang, this remained unverified by independent confirmation.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 3 motives | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
Avon experienced a cybersecurity incident first detected on June 8, 2020, prompting an official filing with the U.S. Securities and Exchange Commission (SEC) the following day. The company disclosed that the event interrupted critical IT systems and partially disrupted business operations across multiple international markets. Distributors in the United Kingdom, Argentina, Brazil, Poland, and Romania reported immediate difficulties accessing Avon's backend ordering platform, which is essential for processing product requests. This operational disruption persisted for at least one week, with systems remaining partially offline during initial recovery efforts. Avon's parent company, Brazilian multinational Natura &Co, maintained a policy of limited transparency, declining to provide substantive details about the incident's nature or scope to both affected distributors and media representatives despite repeated inquiries.

By June 12, Avon submitted a second SEC filing indicating progress in restoring "some affected systems in impacted markets" during the week of June 15. Publicly available restoration timelines showed the Poland and Romania backend systems resumed normal operations by June 16. Unverified reports from Polish cybersecurity firm Niebezpiecznik and an anonymous source suggested the incident involved a ransomware attack by the DopplePaymer group, though Avon never confirmed this attribution and independent verification remained lacking. The company's SEC disclosures emphasized an ongoing investigation into potential unauthorized access to user data while explicitly stating that financial data remained uncompromised due to its ecommerce platform's design, which excluded financial information storage. No further details regarding attack vectors, ransom demands, or data exfiltration were formally released by Avon during the documented recovery period.
