Lee Valley Tools Data Breach Details
On March 12, 2025, Lee Valley became aware of suspicious activity following a breach of its cloud server, which supports the company’s website.
In response, Lee Valley acted swiftly, launching an investigation and bringing in cybersecurity experts to assess and address the situation. The investigation revealed that the breach occurred between October 8, 2024, and March 12, 2025, due to an external hacking incident. While Lee Valley does not store or handle credit card information directly—relying on a third-party processor for transactions—the investigation revealed that an unauthorized party was able to capture certain customer data entered on the website during this time.
As a precaution, Lee Valley is offering 12 months of complimentary credit monitoring and identity restoration services to those affected by the breach. Instructions on how to activate these services are included in the letters sent to impacted individuals.
Personal Information Affected
While the specific data elements vary by individual, the potentially exposed information could include:
- Name
- Address
- Credit card number
- Expiration date
- CVV code