Lush is urging all customers who placed online orders with them between 4 October 2010 and 20 January 2011 to contact their bank as their card details may have been compromised.
Lush has currently halted all online transactions via its website. All customers potentially exposed to this breach were sent an email on 20 January 2011. Lush is advising all customers from the October to January timeframe to contact their bank as the company believes this is a longer timeframe than they believe they were exposed, and should cover all affected customers.
Customer card details have been used fraudulently
Some customers have already experienced misuse of their card details, so all Lush customers who think they could have been affected are being urged to check their bank statements and speak to their bank for advice and to prevent further fraudulent transactions in their name.
Anyone who wishes to speak to Lush directly should call them on their mail order telephone number: 01202 668 545.
Read more about the Lush website hacking security issue on Lush’s website.
Please note: Action Fraud is not responsible for the content on external websites.
To report a fraud, call Action Fraud on 0300 123 2040 or use our online fraud reporting tool.