Avery says card skimmer sat on its website for nearly five months

Organization
Avery Products Corporation
Exploit
Hacking
Industry
Manufacturing

Avery Products Corporation, the California based maker of labels and office supplies, disclosed in January 2025 that its retail website had been running payment card skimming malware for months.

The company said it found the malicious code on December 9, 2024 while investigating a separate ransomware incident. Forensic examiners determined that an attacker had inserted code into the payment card entry form on avery.com on July 18, 2024, capturing details as customers typed them. Avery said the malware affected an application used to process payments rather than its internal systems.

Exposed information included names, billing and shipping addresses, email addresses, phone numbers, payment card numbers with CVV codes and expiration dates, and purchase amounts. Avery said Social Security numbers were not involved. Its notification put the number of affected people at 61,193, though The Record reported in February that Avery's regulatory filings covered roughly 67,000 people and described the skimmer as active until January 5, 2025.

Avery filed notices with regulators in Maine, California, Texas, Massachusetts, Vermont and Iowa, and offered 12 months of free credit monitoring. Having initially said it had no evidence the stolen data had been used, the company later acknowledged that customers had reported fraudulent charges and phishing emails.

Sources