HomeSecurityLouis Vuitton, Dior and Tiffany fined $25 million for violations...

Louis Vuitton, Dior and Tiffany fined $25 million for data breaches

South Korea is sending a clear message to the luxury goods industry by imposing a total of $25 million in fines on Louis Vuitton, Christian Dior Couture and Tiffany. The three iconic brands are accused of failing to implement adequate cybersecurity measures, which allowed attackers to gain unauthorized access to data of more than 5.5 million customers.

Louis Vuitton, Dior and Tiffany

All three companies belong to the Louis Vuitton Moët Hennessy (LVMH) and, according to authorities, the breaches are linked to access to a cloud-based customer management service, which was used to store and process sensitive personal information.

PIPC's research and the problem with SaaS platforms

The South Korean Personal Information Protection Commission (PIPC) highlights that these incidents reveal a growing problem: businesses are increasingly relying on software-as-a-service (SaaS) solutions, but are not always implementing the necessary levels of access control and protection.

See also: Warlock Ransomware breached SmarterTools

The authority clarified that the use of cloud tools does not reduce companies' responsibility. On the contrary, it requires even stricter management, as data is transferred outside of traditional corporate infrastructures.

Louis Vuitton: Malware on employee's device and data leak

In the case of Louis Vuitton, PIPC says the breach began when an employee's device was infected with malware . The incident led to access to the company's SaaS environment and ultimately the leak of data involving 3.6 million customers.

Although the platform is not officially named, Google researchers have linked similar campaigns to the ShinyHunters, which has targeted platforms such as Salesforce. The same threat actor later reportedly claimed to have gained access to LVMH systems.

Louis Vuitton, Dior and Tiffany fined $25 million for data breaches

Authorities note that Louis Vuitton had been using the SaaS tool since 2013, but had not implemented IP-based access restrictions or strong authentication mechanisms for remote access. The fine imposed amounts to $16.4 million, while the company was required to publish the penalty on its website.

See also: European Commission: Breach affects personnel data

Dior: Phishing attack and three-month delay in detection

Christian Dior Couture was breached through a classic phishing attack, in which a customer service representative was tricked into granting access to the SaaS system. The result was the exposure of 1.95 million customer data.

Dior had been using the platform since 2020, but PIPC found serious shortcomings: there were no whitelists, no restrictions on bulk data downloads , and no meaningful audit of access logs. This meant that the breach went undetected for over three months.

Additionally, the company notified PIPC five days after discovering the incident, violating the 72-hour legal limit set by PIPA. Dior's fine amounted to $9.4 million.

Tiffany: Vishing attack and smaller impact

Tiffany faced a similar attack, this time via vishing, or voice phishing, where attackers tricked a support employee into giving them access to the SaaS system.

See also: Man pleads guilty to hacking nearly 600 women's Snapchat accounts

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The impact was significantly smaller, with about 4,600 customers exposed. However, the company was accused of the same shortcomings: lack of IP restrictions, lack of control over bulk data extraction, and delay in notifying affected individuals. The fine reached $1.85 million.

Louis Vuitton, Dior and Tiffany fined $25 million for data breaches

The message from the authorities: Luxury is not exempt from cybersecurity

PIPC emphasized that SaaS solutions do not transfer responsibility for data protection to vendors. Companies remain accountable for the security of their customers, especially when handling high-value data such as purchase history, contact details and personal information.

The incident serves as a reminder that even the largest players in the global market can find themselves exposed if they do not invest in modern cyber protection measures and proper staff training.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS