Security information

Last updated: August 20th 2026

This is the official page where LUISAVIAROMA publishes information about the security incident that affected some of our customer support systems in July 2026. Every update appears here.


In short

Between July 17 and July 27, 2026, unauthorized parties obtained credentials that allowed access to some of our customer support systems and extracted some data held there. The credentials involved were not customer credentials: your own account with us is safe and was never compromised. Your payment information is not involved either: it is not processed by the systems that were accessed.

We have revoked those credentials, reset access, and completed the notification to the Italian Data Protection Authority. The independent forensic team is finalizing the technical review, and this page will reflect any new element as soon as it is available.


What you can do now

The fraudulent messages in circulation use your first name and reference amounts consistent with your actual purchases. That is deliberate, and it is what makes them credible. Four simple rules cover the situation.

  • A refund never requires any action from you. Any refund is credited automatically to the payment method used for the original purchase. We will never ask you to enter your details on a page to receive one.
  • Do not open links contained in emails or text messages. Type our address into your browser. This applies to any message that appears to come from us.
  • Knowing details about you or your purchases is not proof of who is contacting you. LUISAVIAROMA will never ask you for a card number, a security code, a password, or a code received by text.
  • If you entered your details on one of those pages, contact your bank and ask for the card to be blocked, and change any password you may have used elsewhere.

What data is involved

  • Not involved. Payment card information. Your account credentials with us.
  • Involved for the general customer base. First and last name, email address, phone number, country, language, time zone, and the address details you provided, together with aggregate information about your relationship with us (total amount spent, average order, number of orders, currency, loyalty status).
  • Involved for a few hundred customers. The content of past customer service conversations, including our replies. Those conversations span the years 2021 to 2026 and have been reviewed: they contain no payment or bank account details and no identity documents, apart from the few cases covered by a separate individual notice.
  • Involved for a small subset of those customers. In a few cases, the customer had written in the request additional personal information (an IBAN, a partial card reference, or an identity document reference). Each of them has received a dedicated notice that says so, with the precautions to take.
  • Involved for newsletter subscribers without a customer account. Email address, an internal subscription identifier, and newsletter subscription status. Nothing else: for a subscriber who never purchased from us, this is all the information we held.
  • Not extracted, based on current evidence. The details of individual orders.

The fraudulent domain

The messages point to a domain that is not ours. The trick is worth calling out.

  • Real: luisaviaroma.com
  • Fake: luisaviarorna.com (the letter m replaced by the sequence r + n)

Depending on the font, the two look nearly identical. The safest habit is to type the address directly into your browser. We have reported the fraudulent domain to the competent authorities and are working with the relevant platforms to have it removed.


About the email checks

The email systems used to send our customer service notifications were among those accessed during the incident. That is why the fraudulent messages were sent from an address on our real domain and passed the standard authentication checks.

We have replaced the credentials involved: any further fraudulent message would no longer be sent from our systems. Meanwhile, the four rules above are a reliable defense: the sender name is not enough to establish trust.


Timeline

  • July 2026
    • July 17, 2026. The unauthorized activity begins.
    • July 19, 2026. Partial containment on the systems identified at that stage.
    • July 26, 27, 2026. Using one credential that had not yet been rotated, the fraudulent messages are generated and sent.
    • July 27, 2026. We became aware of the full extent of the incident and started the notifications required by law.
    • July 31, 2026. Full containment: all credentials involved have been rotated and the components used by the attacker have been decommissioned.
  • August 20th , 2026. Publication of this page and delivery of the individual notice.

Who received the individual notice, and why

We sent an individual notice to the customers whose data was involved,  and to the newsletter subscribers whose data was involved. Different versions were sent because the data involved is not the same for everyone.

This page is the official channel for everyone, wherever you are. The dedicated mailbox below replies to all customers.


Updates

Update no. 1 ·20th August 2026 

Publication of this page and delivery of the individual notice. The technical analysis on residual verification points continues.


Contacts