The House of Dior (Dior) is sending data breach notifications to U.S. customers informing them that a May cybersecurity incident compromised their personal information. "Our investigation determined that an unauthorized party was able to gain access to a Dior database that contained information about Dior clients on January 26, 2025," reads the notice sent to affected individuals. Louis Vuitton, also a brand of the LVMH group, recently disclosed a data breach that impacted customers in the UK, South Korea, and Turkey. Dior is a French luxury fashion house, part of the LVMH (Moët Hennessy Louis Vuitton) group, which is the world's largest luxury conglomerate. Bill Toulas Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks. The security incident occurred on January 26, 2025, but the company only became aware of it on May 7, 2025, launching internal investigations to determine its scope and impact. Although a spokesperson for the firm didn't respond to our requests for clarification, BleepingComputer learned that the incidents at Louis Vuitton and Dior were part of the same cyberattack. The attack is believed to be linked to the ShinyHunters extortion group, which gained access to LVMH customer information by breaching a third-party vendor's database. The date of the incident matches that of a previous disclosure by Dior, which confirmed impact in South Korea and China. Recipients of the data breach notification are advised to remain vigilant for scams and phishing attempts, and to closely monitor the activity in their financial accounts to identify and report any suspicious activity. This free, editable board report deck helps security leaders present risk, impact, and priorities in clear business terms. The company clarifies that no payment details, such as bank account or payment card information, were contained in the compromised database, so this information remains safe. Meanwhile, the letter encloses instructions on enrolling in a 24-month credit monitoring and identity theft protection package free of charge, redeemable until October 31, 2025.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Mon, 21 Jul 2025 14:35:12 +0000