Skip to main content

Cosmetics company Avon offline after cyber attack

Published on: 19 Jun 2020

Parts of Avon’s website remain offline more than a week after an alleged ransomware attack on its IT systems. 

The attack is understood to have impacted the back-end systems used by its famous sales representatives in multiple countries besides the UK, including Poland and Romania, which are now back online. This has left people unable to place orders with the company.

Avon disclosed the breach in a notification to the US Securities and Exchange Commission (SEC) on 9 June 2020, saying it had suffered a “cyber incident” in its IT environment that had interrupted systems and affected operations.

In a follow-up disclosure on 12 June, Avon said: “Avon … after suffering the cyber incident communicated on 9 June, 2020, is planning to restart some of its affected systems in the impacted markets throughout the course of next week.

“Avon is continuing the investigation to determine the extent of the incident, including potential compromised personal data. Nevertheless, at this point it does not anticipate that credit card details were likely affected, as its main e-commerce website does not store that information.”