[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1z5x2t955gz5e":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":31,"seoTitle":32,"seoTitleEn":33,"seoDescription":32,"seoDescriptionEn":34,"logoUrl":35,"isVerified":4,"isSensitive":36,"isSpamList":36,"isMalware":36,"company":37},"68e3266eda11adda48825286","Luxottica","Luxottica Data Breach","luxottica","luxottica.com","2021-03-16T00:00:00.000Z","2023-05-19T20:24:45.000Z","2026-07-18T23:53:29.716Z","Verified breach record","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fluxottica-confirms-2021-data-breach-after-info-of-70m-leaks-online\u002F",[15,17,18],"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fluxottica-2021-breach-300-million-customer-records-up-for-grabs-online","https:\u002F\u002Fwww.essilorluxottica.com\u002Fen\u002F",77093812,"known",null,"unknown","Critical",[25,26,27,28,29,30],"Dates of birth","Email addresses","Genders","Names","Phone numbers","Physical addresses","\u003Cp>The Luxottica data breach is a verified incident from March 2021 that affected customer data working with numerous brands in the eyewear and optical retail sector. The incident involves retail customer information exposed through a third-party service relationship and affects 77,093,812 unique accounts. Verified data classes include dates of birth, email addresses, gender information, full names, phone numbers, and physical addresses. Passwords, payment card information, financial information, or social security numbers are not included in the verified search scope of this page. Nonetheless, the combined exposure of contact and identity data poses a serious risk in terms of phishing, fake customer service contact, and targeted fraud.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The information revealed in this incident is suitable for identifying the individual and establishing personalized contact. When considered together, the email address, phone number, and physical address allow attackers to send fake messages themed around delivery, warranty, promotions, eyeglass orders, lens renewal, or store accounts. Date of birth and gender information make social engineering scenarios more convincing. Since password data is not among the verified categories, the incident should not be treated directly as a password leak; the main risk is the large-scale combination of personal communication data and the misuse of old customer relationships. If the same information matches with different data lists, phishing attempts can become more targeted.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The breach date is tracked as March 16, 2021, and the listing date as May 19, 2023. The main number on the LeakData side is 77,093,812 unique accounts. Some news about the incident mentions higher raw row or total customer record numbers; these numbers may differ from the number of unique accounts due to duplicate rows, regional records, or multiple rows belonging to the same person. The primary scope shown to the user on this page is the number of unique accounts that are meaningful from an email query result and the verified data classes. The company's own statements also indicate that there is no financial information, password, session information, or social security number; therefore, the disclosure does not go beyond these limits.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The risk is greatest for people who have shopped with Luxottica or associated retail brands, had contact regarding warranties, services, prescription glasses, sunglasses, lenses, store accounts, or online orders. Although customer data from the U.S. and Canada is highlighted in the incident, people who previously had account relationships with the same brands should also check their own email addresses. Leaks containing physical addresses and phone numbers can lay the groundwork for scenarios such as delivery verification, returns processing, promotional coupons, or fake customer satisfaction calls. People who shop on behalf of family members, place orders with a work email, or use the same phone number across different store accounts may also be indirectly at risk.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users who may have been affected should first carefully check unexpected store, delivery, warranty, and campaign messages in their email inbox. Instead of clicking on links in the messages, the official domain name should be typed manually, unexpected attachments should not be opened, and requests for verification codes via phone should be refused. In this incident, the password is not a verified data class; nevertheless, unique passwords and multi-factor authentication should be preferred for store, payment, and email accounts used with the same email address. Due to the exposure of the physical address, themes such as fake shipping notifications, address confirmation, return fees, and customs fees should also be monitored. Suspicious contacts should be verified through known support channels.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>The risk in such retail customer data incidents can persist for a long time; because information such as name, email, phone, and address are fields that do not change easily. Users should close unused store accounts, reduce marketing consents, and regularly review old shopping profiles associated with the same email address. On the institutional side, access by third-party service providers, customer data retention periods, export permissions, and unusual data sharing audits should be more tightly controlled. Customer data should be kept to a minimum, regional data sets should be separated, and incident notifications should be prepared in a clear manner. This approach reduces the impact of a similar incident in the future and clarifies what measures customers should take.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>You can check for a match with the Luxottica data breach by querying your email address on LeakData. If there is a match, stay calm and focus on reducing the risk of fraud against your contact information. Use unique passwords for store accounts, email accounts, and payment services, enable multi-factor authentication, and verify suspicious calls or messages through known official channels. Do not share additional information in unexpected requests that ask for address or phone verification. If you have used the same email address for family, work, or old shopping accounts, check those accounts as well. These steps reduce the likelihood that customer data from 2021 will be reused today for targeted messages and fake support contacts.\u003C\u002Fp>","","Luxottica Data Breach (77.1 Million Reported Records)","Luxottica Data Breach. 77.1 Million reported records were reported. Reported data: Dates of birth, Email addresses, Genders. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fluxottica_com.webp",false,{"name":7,"sector":38,"country":39,"website":10,"websiteArchiveUrl":32,"websiteStatus":32,"websiteCheckedAt":21},"Eyewear and optical retail","Italy"]