Lee Valley Tools Data Breach: Website Payment Card Information Exposed

Lee Valley Tools, Ltd. told customers it found suspicious activity on a cloud server that runs its website back on March 12, 2025. The company says it doesn’t normally store card numbers itself — payment details are supposed to pass directly from a shopper’s device to the card processor — but its investigation found that an unauthorized third party had managed to intercept and capture certain card information as it was being entered on the site. That capturing appears to have gone on for a stretch of nearly five months, from October 8, 2024, until the intrusion was discovered in March 2025. It wasn’t until March 28, 2025, that Lee Valley confirmed specific customers’ personal information was part of what was taken.

This notice went to individuals who made purchases or entered payment details through the Lee Valley Tools website during that window. The letter doesn’t give a total count of how many people were affected, so if you received this letter directly, it’s confirmed that your information was involved — Lee Valley matched your record to the compromised data during its review.

What did the intruder actually get from my card and address?
  • Full name
  • Mailing address
  • Credit card number
  • Card expiration date
  • CVV security code

Because a live card number, its expiration date, and the CVV together are essentially everything needed to make fraudulent charges, Lee Valley is offering 12 months of complimentary credit monitoring and identity restoration through Experian IdentityWorks. The enclosed materials were meant to include an activation code and enrollment link, but those specifics weren’t included in the copy of the letter we reviewed — check your own physical letter for the code, web address, and enrollment deadline, since Experian typically cuts off enrollment after a set date.

Steps to take now that your card details were exposed
  • Call your card issuer right away, ask whether the affected card has already been replaced, and request a new card number if not — don’t wait for a fraudulent charge to appear first.
  • Pull your recent statements line by line for the next several billing cycles, since small test charges often show up before larger fraudulent ones.
  • Enroll in the free Experian IdentityWorks monitoring using the activation code from your letter, and use the full 12 months rather than letting it lapse unused.
  • Consider signing up for a service like Aura or LifeLock, which can alert you if your card number, name, or address shows up somewhere it shouldn’t.
  • Place a fraud alert or credit freeze with Equifax, Experian, and TransUnion if you’re concerned about new-account fraud tied to your name and address.
  • Pull your free annual credit report at annualcreditreport.com to check for accounts you don’t recognize.

If your letter included Experian’s phone number or an engagement number, keep that information handy — it’s how Experian’s team verifies you’re eligible for the identity restoration support described in the notice. Cases involving intercepted website payment data, similar to what happened with Landmark Admin’s breach notification, tend to move fast once discovered, so acting on the card replacement step sooner rather than later is worth the effort.

Leave a Comment