Luxottica has confirmed that one of its partners suffered a data breach in 2021 that exposed the personal information of 70 million customers, after a database was posted for free on hacking forums this month.
See also: Vulnerability in KeePass extracts password

Luxottica is the world's largest eyewear company, a manufacturer of eyeglasses and prescription frames, and the owner of popular brands such as Ray-Ban, Oakley, Chanel, Prada, Versace, Dolce & Gabbana, Burberry, Giorgio Armani, Michael Kors, and many others. The company also operates Eyemed – a vision insurance company in the US.
In November 2022, a member of the defunct hacker forum “Breached” attempted to sell what he claimed was a 2021 database containing 300 million records of personal information relating to Luxottica customers in the United States and Canada.
See also: How to protect your smart home and IoT devices?
According to the seller, the database contained personal customer information, such as email addresses, names, addresses, and dates of birth.
The dump was being offered for private sale at the time on Breached, so it was unclear whether the data had been stolen in a new attack or during two attacks the company had been hit by in 2020.
In August 2020, Luxottica suffered a data breach that exposed the personal information of 829,454 EyeMed and LensCrafters patients. The following month, Luxottica suffered another attack, this time in the form of a ransomware, which shut down its operations in Italy and China.
However, more recently, the database was leaked in its entirety for free on April 30 and May 12, 2020 on various hacking forums, making the data much more accessible to threat actors.
Andrea Draghetti, a top researcher at Italian cybersecurity firm D3Lab, analyzed the leaked data and confirmed to BleepingComputer that it contained 305 million lines, 74.4 million unique email addresses, and 2.6 million unique email domain addresses.

Draghetti also determined that the leak date was March 16, 2021, based on the most recent database– this meant that the data likely came from a previously undisclosed data breach.
After BleepingComputer contacted Luxottica about the published data, the company confirmed that the leaked data came from a security incident that affected a third-party contractor that held customer data.
Information source: bleepingcomputer.com
