Groupe Afflelou
Incident posture
Linked entities
- Victim
- Groupe Afflelou
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
The optical retailer Alain Afflelou reported a cybersecurity incident resulting from a vulnerability in a third‑party provider’s system that allowed unauthorized access to its customer relationship management tool. Exposed data included names, first names, dates of birth, postal addresses, email addresses, phone numbers, purchase histories, quotes, mutual insurance names, dates of last appointments, associated brands, and parental status information; no banking details, social security numbers, visual or auditory correction data, or passwords were compromised. The company stated it had taken measures to prevent recurrence and had no evidence of fraudulent use of the data, while noting that the information could be used in future phishing attempts targeting optical or auditory customers. An investigation is underway and a report has been filed with the French data protection authority.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On April 1, 2025, Alain Afflelou announced via email to its clients that it had been confronted with a cybersecurity incident. The company stated that the incident resulted from a flaw in the system used by one of its providers, which allowed unauthorized access to its customer relationship management tool. The compromised data included names, first names, dates of birth, postal addresses, email addresses, telephone numbers, commercial information such as recent purchases and quotes, the name of the client's mutual insurance, the date of the last appointment, the brand to which the client is attached, and information on parental status. The company emphasized that no banking data, social security numbers, visual or auditory correction data, or passwords were exposed. The number of affected clients was not disclosed.
Alain Afflelou indicated that it had taken the necessary measures to prevent a recurrence and that, at the time of the announcement, it had no knowledge of fraudulent use of the leaked data. The company reported the incident to the French data protection authority (CNIL) and said an investigation was underway to understand how the breach occurred. It warned that the exposed information could potentially be used in future phishing campaigns targeting optical or auditory care customers and advised recipients to contact customer service if they had doubts. Alain Afflelou did not provide further comment when contacted by Tech&Co.
The article notes that Alain Afflelou has been active in the teleconsultation sector since 2022, though this detail is not directly linked to the breach. The announcement was part of a broader wave of cyberattacks affecting French companies and public services. No further technical details about the flaw, the provider involved, or the timeline of detection and containment were provided in the source.
Sources
Sources available to members: 1 source.