← Avery Dennison

2024–2025 Avery Products (Avery Dennison label subsidiary) — payment-card scraper on e‑commerce; ~67k customers (regulatory notices)

2024 67.0K records affected Share on X

Data compromised

E-commerce PII and payment-card track–equivalent fields including CVV per consumer-notification summaries

Technical writeup

Avery Products Corporation, the consumer-label division under Avery Dennison, told regulators that after detecting ransomware on December 9, 2024 a deeper probe uncovered JavaScript payment-card scraping malware on a website checkout flow active from July 18, 2024 through January 5, 2025. The Record summarized multistate breach letters citing roughly 67,000 purchasers with exposure of names, billing/shipping addresses, phones, and full card data including CVV in the worst cases. Company commentary distinguished payment application compromise from enterprise-wide internal ERP; this row links the directory `avery-dennison` slug to the publicly noticed Avery Products incident.

Root cause

Magecart-style web skimmer plus related ransomware discovery sequence (exact same-actor linkage left ambiguous in press)

References