UK-based online contact lens retailer, Vision Direct, has revealed that its customers’ data has been compromised.
Between 12.11am on 3rd November 2018 and 12.52pm on 8th November 2018, the personal and financial details of some of its customers ordering or updating their information on VisionDirect.co.uk was stolen.
The data was compromised when customers entered their data on the website, and was not stolen from the Vision Direct database.
The data included personal and financial details of customers logging in and making changes on the VisionDirect.co.uk website. The compromised information includes full name, billing address, email address, password, telephone number and payment card information, including card number, expiry date and CVV.
There is no risk to data that was already stored in its database, the company said, adding that it has taken the necessary steps to prevent any further data theft. The website is said to be operating normally again, and Vision Direct is working with the authorities to investigate how this theft occurred.
A Vision Direct spokesperson said: “We understand that this incident will cause concern and inconvenience to our customers. We are contacting all affected customers to apologise and continue to inform you of any updates in the next few days.”
Vision Direct has asked anyone who thinks they may have been affected to contact their bank or credit card provider and follow their advice.
It is also emailing customers it believes to have been impacted, providing instructions on how to update their passwords.






