HomeSecurityDior reveals customer data breach

Dior reveals customer data breach

Dior , one of the world's leading fashion houses, has revealed that a cyberattack led to a data breach affecting customers of its Dior Fashion and Dior Accessories divisions. A company spokesperson told BleepingComputer that the incident was due to unauthorized access by an external party , which resulted in the leakage of certain customer information.

Dior data breach

Dior said it had taken immediate action, activating internal security teams and working with consultants cybersecurityto fully assess and contain the incident. An in-depth investigation into the exact extent of the breach is currently underway.

According to a company announcement, the leaked data does not include sensitive information such as passwords, bank accounts or payment details, as these are stored in a separate database that was not affected by the attack.

See also: Marks & Spencer: Cyberattack led to data breach

Dior assured that it is informing the relevant regulatory authorities and customers who may have been affected by the data breach (in compliance with relevant data protection legislation).

"Protecting the privacy and security of our customers is our top priority," the company said in a statement, while expressing regret for the disruption caused by the incident.

It is worth noting that according to the information so far, users from Korea and China are among those affected.

Dior data breach

Dior declined to disclose the exact number of customers affected by the recent data breach, but sources say the company's website in South Korea was among those affected. Meanwhile, reports from users in China have also suggested they have received notifications from the fashion house about a breach of their personal data.

Dior reveals customer data breach

Screenshots of the alerts released online show that the incident was detected on May 7, 2025, and involved unauthorized access to customer data. The information that appears to have been exposed includes:

  • Full name
  • Sex
  • Phone number
  • Email address
  • Mailing address
  • Purchase history

See also: Insight Partners: Data breach following cyberattack

The announcement posted on Dior's Korean e-shop confirms that the breach occurred on May 7, suggesting that it was an isolated incident with an international dimension.

However, the case is also taking on legal implications: local media in South Korea are reporting that Dior may face scrutiny from regulators due to late or incomplete notification of the incident.

The company, for its part, calls on customers to be particularly vigilant against possible phishing emails or suspicious attempts to steal information, and urges them to immediately report any incident related to misuse of the Dior brand.

So far, there have been no official announcements on the total scope of countries or the number of customers affected, leaving several questions open about the dimensions of the incident.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Pearson: Cyberattack led to data breach

How can companies avoid cyberattacks and data breaches?

The Dior data breach shows that companies need to take protective measures (preventive) to avoid such situations:

  • Implementation of multi-layered security (defense in depth)
    Combination of firewall, antivirus, intrusion detection/prevention systems (IDS/IPS), etc.
  • Encryption of sensitive data
    both during storage and during transfer (end-to-end encryption).
  • Software updates & patches
    Regular application of updates to address vulnerabilities.
  • Access management (access control)
    Minimization of rights per role, use of Least Privilege & Zero Trust principles.
  • Multi-factor authentication (MFA)
    Strengthen security for user and administrator accounts.
  • Regular penetration tests & vulnerability assessments
    Identify and address security gaps proactively.
  • Staff training in cybersecurity.
    Tackling phishing, social engineering and using good security practices.
  • Backup systems & disaster recovery plan
    Ensuring recovery in the event of an attack or data loss.
  • Event logging & real-time monitoring (SIEM systems)
    Immediate detection and response to suspicious activity.
  • Compliance with regulations (GDPR, ISO 27001, etc.)
    Ensuring that the security policy is complete and controlled.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS