South Korea is sending a clear message to the luxury goods industry by imposing a total of $25 million in fines on Louis Vuitton, Christian Dior Couture and Tiffany. The three iconic brands are accused of failing to implement adequate cybersecurity measures, which allowed attackers to gain unauthorized access to data of more than 5.5 million customers.

All three companies belong to the Louis Vuitton Moët Hennessy (LVMH) and, according to authorities, the breaches are linked to access to a cloud-based customer management service, which was used to store and process sensitive personal information.
PIPC's research and the problem with SaaS platforms
The South Korean Personal Information Protection Commission (PIPC) highlights that these incidents reveal a growing problem: businesses are increasingly relying on software-as-a-service (SaaS) solutions, but are not always implementing the necessary levels of access control and protection.
See also: Warlock Ransomware breached SmarterTools
The authority clarified that the use of cloud tools does not reduce companies' responsibility. On the contrary, it requires even stricter management, as data is transferred outside of traditional corporate infrastructures.
Louis Vuitton: Malware on employee's device and data leak
In the case of Louis Vuitton, PIPC says the breach began when an employee's device was infected with malware . The incident led to access to the company's SaaS environment and ultimately the leak of data involving 3.6 million customers.
Although the platform is not officially named, Google researchers have linked similar campaigns to the ShinyHunters, which has targeted platforms such as Salesforce. The same threat actor later reportedly claimed to have gained access to LVMH systems.

Authorities note that Louis Vuitton had been using the SaaS tool since 2013, but had not implemented IP-based access restrictions or strong authentication mechanisms for remote access. The fine imposed amounts to $16.4 million, while the company was required to publish the penalty on its website.
See also: European Commission: Breach affects personnel data
Dior: Phishing attack and three-month delay in detection
Christian Dior Couture was breached through a classic phishing attack, in which a customer service representative was tricked into granting access to the SaaS system. The result was the exposure of 1.95 million customer data.
Dior had been using the platform since 2020, but PIPC found serious shortcomings: there were no whitelists, no restrictions on bulk data downloads , and no meaningful audit of access logs. This meant that the breach went undetected for over three months.
Additionally, the company notified PIPC five days after discovering the incident, violating the 72-hour legal limit set by PIPA. Dior's fine amounted to $9.4 million.
Tiffany: Vishing attack and smaller impact
Tiffany faced a similar attack, this time via vishing, or voice phishing, where attackers tricked a support employee into giving them access to the SaaS system.
See also: Man pleads guilty to hacking nearly 600 women's Snapchat accounts
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The impact was significantly smaller, with about 4,600 customers exposed. However, the company was accused of the same shortcomings: lack of IP restrictions, lack of control over bulk data extraction, and delay in notifying affected individuals. The fine reached $1.85 million.

The message from the authorities: Luxury is not exempt from cybersecurity
PIPC emphasized that SaaS solutions do not transfer responsibility for data protection to vendors. Companies remain accountable for the security of their customers, especially when handling high-value data such as purchase history, contact details and personal information.
The incident serves as a reminder that even the largest players in the global market can find themselves exposed if they do not invest in modern cyber protection measures and proper staff training.
Source: www.bleepingcomputer.com
