Direct Clothing
Disclosed Jul 18, 20224 years agoConfirmed
UK ICO reprimand for security failings
On 19 August 2021, Direct Clothing Co. (UK) Limited (DCCUK) were contacted by a customer who advised that their payment card had been defrauded after using DCCUK’s website. An investigation by DCCUK found that a malicious code had been introduced to the website which allowed an unknown third party to obtain the payment card details of website customers. The third party obtained access to DCCUK’s environment via a WordPress vulnerability, although the specific vulnerability could not be determined due to the number of vulnerabilities present at the time of the incident. DCCUK believed that a third party IT provider was responsible for the security and maintenance of the affected website, however, this was not the case.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Jul 18, 2022 |
| Attack | Vendor breach |
| Data exposed | Not stated |
| Sector | Retail · GB |
| Status | Confirmed |
| Lawsuit or fine | UK ICO reprimand (2022-07-18) |
Sources
| Source | |
|---|---|
| UK ICO reprimand: Direct Clothing Co. (UK) Limitedico.org.uk · Regulator | Regulator |
Notices filed
| Where | Filed | People |
|---|---|---|
| UK ICOregulator:GB | Jul 18, 2022 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (UK ICO), confirmed by UK ICO. Record counts are as reported. Not legal advice.