Menu
Browse

Cyber Incident Victim: Groupe Afflelou

Date:

Nov 2025

Location:

France

Summary

Alain Afflelou, an optician chain, disclosed a cybersecurity incident resulting from a vulnerability in a third‑party provider’s system that allowed unauthorized access to its customer relationship management tool. Exposed personal data include names, first names, dates of birth, postal addresses, email addresses, phone numbers, commercial details such as recent purchases and quotes, mutual insurance information, date of the last appointment, the brand with which the customer is affiliated, and parental status. The company stated that no banking data, social security numbers, visual or auditory correction details, or passwords were compromised and that the number of affected clients remains unknown. It said there is currently no evidence of fraudulent use of the leaked information and that it has taken steps to prevent recurrence while an investigation, including a notification to the French data protection authority, continues.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On April 1, 2025, Alain Afflelou informed its customers via email that it had faced a cybersecurity incident. The company explained that the incident stemmed from a vulnerability in the system of one of its service providers, which allowed unauthorized access to its customer relationship management (CRM) tool. The breach was identified after the provider’s flaw was exploited, leading to exposure of personal data stored in the CRM. Alain Afflelou stated that it became aware of the incident and promptly notified affected individuals.

Cyber Incident Image

The compromised data included customers’ names, first names, dates of birth, postal addresses, email addresses, telephone numbers, commercial information such as recent purchases and quotes, the name of their mutual insurance provider, the date of their last appointment, the optical brand to which they are attached, and information about parental status. The company explicitly noted that no banking details, social security numbers, visual or auditory correction data, or passwords were part of the exposed dataset. Alain Afflelou also indicated that, at the time of notification, it had no evidence of fraudulent use of the leaked information.

In its communication, Alain Afflelou said it had taken the necessary measures to prevent a recurrence of such an incident. It reported that an investigation was underway to determine the exact cause and scope of the breach, and that it had filed a report with the French data protection authority (CNIL). The company noted that the exposed information could potentially be used in future phishing campaigns specifically targeting optical or auditory health‑related data. Alain Afflelou stated that it would continue to monitor the situation and keep customers informed of any developments.

Sources
Sources available to members
1 source