Data breach
Luxottica
- Records
- 299,866,280
- Breach date
- 16 March 2021Estimated
- Added
- 1 December 2024
What was exposed
4 types of data · 1 more reported
- Names279,276,048
- Home addresses229,775,755
- Phone numbers198,502,564
- Email addresses114,524,999
- Dates of birthReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In March 2021, attackers stole the personal information of tens of millions of Luxottica customers from a third-party contractor that managed the eyewear giant's customer data, a breach the company only confirmed two years later after the stolen database surfaced on hacking forums. The dataset tied to this incident contains nearly 300 million records, including more than 114.5 million email addresses, roughly 198.5 million phone numbers, nearly 279.3 million names, and nearly 229.8 million home addresses. Luxottica, whose brands include Ray-Ban, Oakley, LensCrafters, and Persol, confirmed the breach in May 2023 after the data appeared online for free.
Breach Timeline
March 16, 2021: The most recent record in the stolen database dates to this day, which researcher Andrea Draghetti identified as the point when the data was extracted.
November 2022: A user on the now-defunct Breached hacking forum attempted to sell a database of about 300 million Luxottica customer records from the United States and Canada, and Luxottica says it first learned of the incident from this dark web post.
April 30 to May 12, 2023: The database was posted for free on leak sites, making it broadly accessible.
May 2023: After being contacted by BleepingComputer, Luxottica confirmed the breach and said roughly 70 million customers were affected.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Email addresses (114,524,999)
Phone numbers (198,502,564)
Names (279,276,048)
Home addresses (229,775,755)
Luxottica's own statement to BleepingComputer listed an additional field: dates of birth.
Not every individual is affected by every type of data listed here.
The company said the exposed data does not include financial information, Social Security numbers, or login credentials. It also stated that its own systems were not breached and that the incident originated at a third party.
What Are the Potential Risks for Affected Individuals?
The combination of names, home addresses, phone numbers, email addresses, and dates of birth is valuable for targeted phishing and social engineering. Scammers can use these details to craft convincing messages or calls that reference real, personal information, making fraudulent claims about deliveries, warranties, or account problems harder to spot.
Because this dataset circulated freely on hacking forums since spring 2023, the information is available to a wide range of malicious actors, not just the original thieves. The data can also support identity fraud attempts when combined with other sources, and unwanted spam or robocalls are a near-term nuisance for anyone whose phone number is included.
What Is Luxottica Doing in Response?
Luxottica confirmed the breach in May 2023 and attributed it to a security incident at a third-party contractor holding customer data. The company said it reported the incident to the FBI and Italian law enforcement, notified the Italian data protection authority, and was evaluating further notification obligations. It also stated that it began sending data breach notification letters to affected individuals. Luxottica said the owner of the forum where the data appeared had been arrested by the FBI. The company's investigation was ongoing at the time of its statement.
What Should You Do If You Were Affected?
Watch for phishing. Expect emails, texts, or calls that reference your name, address, or a Luxottica brand. Do not click links or share information with unsolicited contacts, and verify any claim independently.
Be alert to scams that use your home address. Criminals with address data may impersonate delivery services, retailers, or government agencies.
Check your accounts for unusual activity. Although passwords were not exposed, reusing an email address across services means criminals can still attempt credential stuffing. Use unique passwords and enable two-factor authentication where available.
Monitor for identity fraud. Dates of birth and addresses are building blocks for identity theft. Review financial statements and consider placing a fraud alert with credit bureaus if you see anything unusual.
Look for official notification. If you lived in the United States or Canada and bought from Luxottica or its brands, watch your mail and email for a notification letter from the company.
In the news
- BleepingComputer: Luxottica confirms 2021 data breach after info of 70M leaks onlinebleepingcomputer.com (opens in a new tab)
- Bitdefender: Luxottica 2021 breach: 300 million customer records up for grabs onlinebitdefender.com (opens in a new tab)
- IT Governance: Cyber attacks and data breaches in review, May 2023itgovernance.eu (opens in a new tab)
- Digital Watch: Luxottica admits to 2021 data breach that exposed personal information of 70 million customersdig.watch (opens in a new tab)
