Incident Of The Week: UK-Based Vision Direct Discloses Data Breach

Magecart Group May be Responsible

Add bookmark

UK eye care company Vision Direct has disclosed an undetermined number of customers’ financial and other personal data was leaked earlier this month after a breach of its website.

The breach occurred between Nov. 3 and Nov. 8, according to Vision Direct, which claims to be the largest e-tailer of contact lenses and eye care products and services in Europe. It identified 16,300 people as being at risk, the company told the BBC.

It has since been resolved and “Vision Direct has taken the necessary steps to prevent any further data theft, the website is working normally, and we are working with the authorities to investigate how this theft occurred, ’’ the company said in a statement.

The breach occurred when “fake Google Analytics JavaScript designed to capture card details, appears to have been planted by the prolific cybercrime gangs known as Magecart,” according to Data Breach Today. Magecart refers to a group of persistent credit card skimming hackers. There are at least six distinct groups operating Magecart skimming scams, each with their own approach, according to TechCrunch.

See Related: Incident Of The Week: May Eye Care And Health First Both Report Breaches Of Customer Information

In addition to Vision Direct’s UK site, its local sites in Ireland, the Netherlands, France, Spain, Italy and Belgium were also impacted.

A Vision Direct spokeswoman told the BBC that the financial data of 6,600 customers is believed to have been compromised, while another 9,700 people had personal data but not card details exposed.

Included among the compromised personal information were patient names, phone numbers, email addresses, passwords and credit card information, Vision Direct said. While storing CVV data in any form is prohibited by Payment Card Industry Data Security Standard specifications, the company said if it was entered between 12:11 GMT on Nov. 3 and 12:52 p.m. on Nov. 8th, it may have been compromised.

It is particularly serious when card security codes are breached, cyber security researcher Scott Helme told the BBC. Helme also told The Register the attack appeared to be similar to ones suffered by British Airways and Ticketmaster. Both of those companies were also targeted by Magecart cyber hackers exploiting "third party dependencies or weaknesses in the application itself," The Register reported.

Customers using PayPal during the compromised period were not impacted by the breach, according to Vision Direct. Any customer who logged in or updated details on their Vision Direct UK account during that time period is advised to contact their bank or credit card company for advice, the company recommended. RiskIQ advises retail website owners to take a layered approach to security with patches and segregated servers, TechCrunch reported.


Upcoming Events

16th Automotive Cybersecurity Summit 2026

March 18 - 19, 2026

Sheraton Ann Arbor Hotel, Ann Arbor, Michigan

16th Automotive Cybersecurity Summit 2026

Digital Identity Week

1st - 2nd September 2026

Sydney, Australia

Digital Identity Week

Latest Webinars

From Dependencies to Defences: Navigating Software Supply Chain Security

2025-09-24

11:00 AM - 12:00 PM SGT

Learn how to defend your software supply chain from dependency threats and build resilient security...

Unpacking global regulatory frameworks to enhance third-party operational resilience

2024-11-14

11:00 AM - 12:00 PM EST

Join this webinar to explore the resilience-focused requirements of DORA, NIS2 and other global regu...

Preventing financial and reputational risk with process intelligence

2024-05-23

11:00 AM - 12:00 PM EDT

Learn how to manage risk stemming from poorly controlled processes in a collaborative way

Recommended

info@cshub.com/r/n

We hope you enjoy All Access from CS Hub!!<\/p>\r\n<p>Best Regards,<\/p>\r\n<p><a href=https://www.cshub.com/"https:////www.cshub.com///" target=\"_blank\">CS Hub Team<\/a><\/p>\r\n<p>P.S. Be sure to check out our other upcoming <a href=https://www.cshub.com/"https:////www.cshub.com//events?filter_format=ONLINE\%22 target=\"_blank\">All Access events here<\/a>.<\/p>\r\n<p>--------------------------------<\/p>\r\nConnect with us on Social Media: <a href=https://www.cshub.com/"https:////www.linkedin.com//groups//12067996///" target=\"_blank\">LinkedIn<\/a> | <a href=https://www.cshub.com/"https:////twitter.com//CSHubUSA/" target=\"_blank\">Twitter<\/a><\/p>\r\n<p>--------------------------------<\/p>\r\n<p>FAQS<\/p>\r\n<p><b>Can I invite my colleagues?<\/b><br>Yes of course! Please send them this link so they can register for free! [WebUrl]<\/p>\r\n\r\n<p><b>How do I access the sessions?<\/b><br>\r\nAll Access is run on Zoom Events. You should receive an email shortly from Zoom Events with your unique All Access link to the event lobby. Please hold on to that email ahead of the event. We\u2019ll also send you a reminder 24 hours before we go live!<\/p>\r\n\r\n<p><b>Will the agenda be updated?<\/b><br>\r\nYes, the agenda will be continuously updated on the website with the latest sessions & speakers. As we get closer to the event, also look out for our weekly updates which will also include the latest updates information and link to access the event.<\/p>\r\n<p><b>Can I access the sessions On Demand?<\/b><br>\r\nEvery session will be available after the event via the event lobby. We\u2019ll also send you a reminder about the On Demand sessions which will be sent to you after the event is over.<\/p>\r\n<p>--------------------------------<\/p>\r\n<p>RELATED RESOURCES TO READ BEFORE YOUR EVENT<\/p>\r\n<ul>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//executive-decisions//reports//cs-hub-mid-year-market-report-2022?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CS Hub Mid-Year Market Report 2022<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//ciso-strategies-for-proactive-threat-prevention?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CISO strategies for proactive threat prevention<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//how-to-strengthen-email-security-and-protection-against-advanced-ransomware-attacks?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">How to strengthen email security and protection against advanced ransomware attacks<\/a><\/li>\r\n<\/ul>","event_registration_srs_confirmation_email":null,"assets_from_cdn":true},"bant_disabled":null,"sponsorship_disclaimer":null,"sponsorship_disclaimer_text":null,"sponsorship_disclaimer_checkbox_disabled":null,"ext_treat_id":null,"recording_url":null,"file_attachment":null,"ingo_enabled":null,"ingo_activator_id":null,"ingo_autofiller_id":null,"ingo_amplifier_id":null,"ingo_authorizer_id":null,"restricted_content":0,"featured_events_embedded":[],"featured_content_embedded":[],"featured_content_portal_embedded":null}" >