Skip to content

Direct Clothing

Disclosed Jul 18, 20224 years agoConfirmed

Official notice

UK ICO reprimand for security failings

On 19 August 2021, Direct Clothing Co. (UK) Limited (DCCUK) were contacted by a customer who advised that their payment card had been defrauded after using DCCUK’s website. An investigation by DCCUK found that a malicious code had been introduced to the website which allowed an unknown third party to obtain the payment card details of website customers. The third party obtained access to DCCUK’s environment via a WordPress vulnerability, although the specific vulnerability could not be determined due to the number of vulnerabilities present at the time of the incident. DCCUK believed that a third party IT provider was responsible for the security and maintenance of the affected website, however, this was not the case.

What is known

People affectedNot stated in the sources we have
DisclosedJul 18, 2022
AttackVendor breach
Data exposedNot stated
SectorRetail · GB
StatusConfirmed
Lawsuit or fineUK ICO reprimand (2022-07-18)

Sources

Source
UK ICO reprimand: Direct Clothing Co. (UK) Limitedico.org.uk · Regulator

Notices filed

WhereFiledPeople
UK ICOregulator:GBJul 18, 2022
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (UK ICO), confirmed by UK ICO. Record counts are as reported. Not legal advice.

Everything about Direct Clothing

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.