Tiffany
Incident posture
Timeline
Summary
A voice phishing attack targeting an employee resulted in the exposure of personal details belonging to approximately 4,600 individuals associated with the luxury brand. The incident is part of a broader campaign that exploited social engineering techniques to gain access to a SaaS platform, compromising customer data across multiple major organizations without relying on infrastructure vulnerabilities. South Korea's Personal Information Protection Commission subsequently imposed a fine of roughly $1.6 million on the company for the breach, which was linked to extortion activity by a threat group operating in the same campaign that impacted other well-known brands.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
South Korea's Personal Information Protection Commission (PIPC) announced fines totaling approximately 36 billion Korean won ($25 million) against three luxury brands owned by Paris-based conglomerate LVMH, following a series of data breaches that compromised the personal information of millions of individuals. The fines targeted Louis Vuitton, Dior, and Tiffany, and were issued in response to separate but related incidents connected to a broader campaign targeting organizations that use a specific SaaS platform, which the regulator did not name publicly.
According to the PIPC, Louis Vuitton received the largest fine, approximately $15 million, after cybersecurity failures led to employee devices becoming infected with malware. This incident resulted in the exposure of information belonging to roughly 3.6 million individuals. Dior was fined the equivalent of more than $8.4 million after an employee fell victim to a voice phishing attack, which led to the exposure of data belonging to approximately 1.95 million individuals. Tiffany was ordered to pay $1.6 million for a separate incident in which the organization also fell victim to a voice phishing attack, resulting in the exposure of details belonging to roughly 4,600 people.
The data breaches involving Louis Vuitton, Dior, and Tiffany were linked to a SaaS platform intrusion. Although the PIPC did not publicly identify the platform, Louis Vuitton, Dior, and Tiffany were among dozens of major organizations targeted the previous year in a campaign aimed at Salesforce customers. An extortion group identifying itself as "Scattered LAPSUS$ Hunters" claimed responsibility for obtaining millions of data records after gaining access to the Salesforce instances of the targeted organizations. The attackers relied on social engineering techniques to compromise these environments rather than exploiting vulnerabilities in the underlying Salesforce infrastructure or products. As a result, the breaches at the three LVMH brands stemmed from human-targeted intrusion tactics, including voice phishing schemes directed at employees of Dior and Tiffany, and malware infections on Louis Vuitton employee devices.
Sources
Sources available to members: 1 source.