$1.5 Million Fine for Warby Parker for Failing to Protect Customer Data
In December 2018, the U.S. Department of Health and Human Services’ (HHS) Office for Civil Rights (OCR) had started an investigation after the eyewear company Warby Parker reported “unusual, attempted log-in activity” on its website. Their investigation led to the fact that Warby Parker had suffered a major credential stuffing cyber-attack in which threat actors accessed a trove of sensitive information of almost 200,000 customers. The stolen information included customer names, addresses, payment details, and eyewear prescription data. Subsequently, two smaller additional breaches in April 2020 and June 2022 reinforced Warby Parker’s pattern of recurring cyber vulnerabilities.
We use cookies to offer you a better browsing experience and to analyze site traffic. By using our site, you consent to our use of cookies.
Essential Cookies
Site Analytics
Essential Cookies
These cookies are necessary for certain areas of the site to function. They are used for access to secure areas of the website and to help us comply with legal requirements like GDPR.
Site Analytics
These cookies are used to collect information about how users use our site. We use these to improve how our website works.