CSIDB logo
Threat actor

Christian Dior

Attribution profile

Type
Criminal
Location
Russia
Known incidents
1 incident
First seen
2022-10-07
Last seen
2022-10-07
Updated
2026-07-30 22:23
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor operates under the alias Christian Dior. Open source references associate this alias with a presence in Russia. The actor came to public attention following a data breach disclosed in October 2022. No further personal details about the individual or group have been released.

The breach targeted MyDeal, an Australian online retail marketplace. MyDeal operates as a subsidiary of Woolworths and serves customers primarily in Australia. The actor’s actions were directed at obtaining personal information for subsequent sale. The stolen data included names, email addresses, phone numbers, delivery addresses and, for a subset, birth dates.

Initial access was achieved by leveraging compromised user credentials to enter the company’s CRM system. Once inside, the actor viewed and exported customer records without deploying malware. To validate the intrusion, the actor shared screenshots purportedly showing the internal Confluence server and an AWS single‑sign‑on prompt. The data was then offered for sale on a hacking forum, with the actor initially advertising approximately one million records.

The actor later provided samples of the stolen data, exposing details for 286 individuals to prove authenticity. Woolworths confirmed that its own platforms remained separate and were not affected by the incident. No public attribution links the actor to a state sponsor, criminal consortium or any larger threat group. The MyDeal breach remains the only publicly reported operation associated with the Christian Dior alias.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB