Avery Products Corporation Data Breach: What the Notification Letter Means for You

Avery Products Corporation has begun mailing letters to customers after discovering that an unauthorized actor planted malicious software on its avery.com website. Avery says it first learned of a ransomware attack affecting certain internal systems on December 9, 2024, and that its subsequent investigation traced the malicious code back to July 18, 2024. During that window, the software was quietly scraping payment card details entered by shoppers checking out on the site. Avery initially found no proof that the scraped data had actually been taken off its systems, but after receiving reports from customers describing fraudulent charges and phishing emails, the company concluded that information may in fact have been acquired and used.

The letter is addressed to individuals whose personal and payment information was confirmed present in the affected system during the incident window. Avery notes that the exact fields exposed can differ from person to person, and that it does not collect Social Security numbers, driver’s license numbers, or dates of birth, so those items were not part of this incident.

What did Avery’s investigation confirm was exposed?
  • First and last name
  • Billing address
  • Shipping address
  • Email address (if provided)
  • Phone number (if provided)
  • Payment card number along with the CVV and expiration date
  • Purchase amount from the transaction

Avery is covering the cost of 12 months of credit monitoring, credit reporting, and credit score tracking through Cyberscout, a TransUnion company, and is also offering proactive fraud assistance to anyone who needs help responding to misuse of their information. To activate the free monitoring, go to https://bfs.cyberscout.com/activate and enter the unique enrollment code printed in your letter; Avery states you must sign up within 90 days of the letter’s date, and the service is not available to anyone under 18.

Practical steps if your card details were caught in this breach
  • Enroll in the free Cyberscout/TransUnion credit monitoring before the 90-day window closes, since it costs you nothing and flags changes to your credit file the same day they occur.
  • Call your card issuer to ask about a replacement card number if you used a payment card on avery.com during the affected period, especially if you’ve noticed any unfamiliar charges.
  • Watch closely for phishing emails referencing Avery, your order, or your account — Avery specifically mentions receiving reports of phishing tied to this incident.
  • Pull your free annual credit reports from all three bureaus at annualcreditreport.com and look for accounts or inquiries you don’t recognize.
  • Consider placing a fraud alert or security freeze with Experian, TransUnion, or Equifax if you want an extra layer of protection against new accounts being opened in your name.
  • For ongoing peace of mind, consider signing up for a service like Aura or LifeLock, which can alert you if your information appears elsewhere, such as on dark web marketplaces.
  • Keep an eye on your bank and card statements for the next several months, not just the next few weeks, since stolen card data can surface and be used well after the initial breach.

If you have questions about your specific notice, Avery Products Corporation can be reached by mail at 50 Pointe Drive, Brea, CA 92821, or by phone at (714) 674-8500.

Leave a Comment