Louis Vuitton, the flagship brand of the LVMH, has confirmed that the successive personal data breaches recorded in the United Kingdom, South Korea and Turkey are related to a single cybersecurity incident. Initial indications link the case to the notorious cyber-extortion group ShinyHunters, which is behind a number of recent attacks on multinationals.

Violation with a global dimension
Louis Vuitton began notifying customers of the incident in early July 2025. First in South Korea , then in Turkey , and most recently in the United Kingdom , the notifications revealed unauthorized access to personal data , but did not include financial or payment information.
According to the company's official announcement: "Despite the security measures taken, on July 2, 2025, we learned of a personal data breach resulting from the theft of certain personal data of some of our customers following unauthorized access to our system."
See also: Century Support Services breach affects 160,000 people
The company stated that cybersecurity teams were immediately mobilized, technical measures were implemented to mitigate the threat, and the relevant regulatory authorities, such as the ICO in the United Kingdom.
Connecting with ShinyHunters and third-party vendors
The incident appears to extend beyond Louis Vuitton, affecting the LVMH group as a whole, as similar breaches have been reported in recent months by other luxury brands, such as:
- Tiffany & Co. (April 2025)
- House of Dior (May 2025)
As sources report to BleepingComputer, the attack is attributed to ShinyHunters, an active cybercriminal group, which gained access through a breach of a third-party vendor that works with many luxury brands.
The same attack is likely linked to the Adidas, which was revealed in May and also affected customers in South Korea and Turkey.
Who are ShinyHunters?
ShinyHunters is one of the most active and notorious threat actors . They have been active since 2020 and have a rich history of breaches that includes companies such as:
- Salesforce
- PowerSchool
- Snowflake
- Santander
- Ticketmaster
- AT&T
- Advance Auto Parts
- Neiman Marcus
- Cylance
Luxury under siege – New fronts in cyberspace
Recently, French police arrested five people allegedly associated with the group and the management of the BreachForum, through which stolen data was being distributed. Despite the arrests, it is believed that core elements of the group remain active, and attacks are expected to continue.
See also: Episource: Notifies customers of recent data breach
The Louis Vuitton incident reveals a broader trend of targeted attacks against the luxury retail industry, which attracts high-profile customers and sensitive personal data. The attacks on luxury brands:
- have a symbolic character (brand visibility),
- are used for extortion or data leakage with financial motives, and
- linked to breaches through supply chains and third-party suppliers.
Experts point out that as large groups focus on customer experience and omnichannel technology, the attack surface for digital criminals increases. Digitalization in the luxury fashion sector poses a dual challenge: a technological opportunity but also a growing risk.
See also: Bitcoin Depot: Data Breach Affects 27,000 Customers
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

How can luxury brands be protected ?
1. Supply chain assessment and protection (supply chain security)
- Many attacks are launched through third-party vendors or external partners.
- Every brand should conduct regular audits and risk assessments at all technological and human points of connection with external providers.
- Signing a security clause in contracts with third parties is now necessary.
2. Staff training & awareness raising
- Users remain the most vulnerable link. Targeted phishing attacks can unlock systems.
- Regular employee training, especially in customer service, marketing, and IT departments, is critical.
- Strengthening a “zero trust” and least privilege policies.
3. Integrate modern cloud and AI security solutions
- The transition to cloud-first infrastructures requires modern SIEM, EDR/XDR and AI-based threat detection.
- Continuous incident monitoring (SOC) and real-time response should now be considered key components of the strategy.
4. Crisis management and transparency towards customers
- Having an Incident Response Plan is absolutely essential .
- Communication with customers must be direct, honest and responsible.
- Brands that choose transparency and speed in their response gain trust even after a breach.
5. Collaboration with specialized providers and public authorities
- Working with cybersecurity experts is not a luxury — it's a necessity.
- Cyberattacks are transnational in nature, and cooperation with regulatory authorities and information exchange platforms enhances prevention.
Source: www.bleepingcomputer.com
