Cyber Incident Victim: Groupe Afflelou
Date:
Nov 2025
Location:
France
Summary
Alain Afflelou, an optician chain, disclosed a cybersecurity incident resulting from a vulnerability in a third‑party provider’s system that allowed unauthorized access to its customer relationship management tool. Exposed personal data include names, first names, dates of birth, postal addresses, email addresses, phone numbers, commercial details such as recent purchases and quotes, mutual insurance information, date of the last appointment, the brand with which the customer is affiliated, and parental status. The company stated that no banking data, social security numbers, visual or auditory correction details, or passwords were compromised and that the number of affected clients remains unknown. It said there is currently no evidence of fraudulent use of the leaked information and that it has taken steps to prevent recurrence while an investigation, including a notification to the French data protection authority, continues.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On April 1, 2025, Alain Afflelou informed its customers via email that it had faced a cybersecurity incident. The company explained that the incident stemmed from a vulnerability in the system of one of its service providers, which allowed unauthorized access to its customer relationship management (CRM) tool. The breach was identified after the provider’s flaw was exploited, leading to exposure of personal data stored in the CRM. Alain Afflelou stated that it became aware of the incident and promptly notified affected individuals.

The compromised data included customers’ names, first names, dates of birth, postal addresses, email addresses, telephone numbers, commercial information such as recent purchases and quotes, the name of their mutual insurance provider, the date of their last appointment, the optical brand to which they are attached, and information about parental status. The company explicitly noted that no banking details, social security numbers, visual or auditory correction data, or passwords were part of the exposed dataset. Alain Afflelou also indicated that, at the time of notification, it had no evidence of fraudulent use of the leaked information.
In its communication, Alain Afflelou said it had taken the necessary measures to prevent a recurrence of such an incident. It reported that an investigation was underway to determine the exact cause and scope of the breach, and that it had filed a report with the French data protection authority (CNIL). The company noted that the exposed information could potentially be used in future phishing campaigns specifically targeting optical or auditory health‑related data. Alain Afflelou stated that it would continue to monitor the situation and keep customers informed of any developments.
