Louis Vuitton
Incident posture
Linked entities
- Victim
- Louis Vuitton
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
South Korea's Personal Information Protection Commission imposed significant fines totaling approximately $25 million on LVMH subsidiaries Louis Vuitton, Dior, and Tiffany following a major data breach that compromised the personal information of millions of customers across the three brands. The incident stemmed from a SaaS platform intrusion, with the brands among numerous organizations targeted in a campaign aimed at Salesforce customers by the Scattered LAPSUS$ Hunters extortion group, who used social engineering tactics rather than exploiting technical vulnerabilities. Specifically, employee devices were infected with malware at Louis Vuitton, while employees at Dior and Tiffany fell victim to voice phishing attacks, resulting in the exposure of data belonging to roughly 3.6 million individuals at Louis Vuitton, 1.95 million at Dior, and approximately 4,600 at Tiffany.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
South Korea's Personal Information Protection Commission announced fines totaling 36 billion Korean won against several luxury brands owned by the Paris-based multinational conglomerate LVMH, following data breaches that exposed the personal information of millions of individuals. The regulator imposed the largest penalty on Louis Vuitton, fining the company roughly $15 million for cybersecurity failures tied to its operations in the country. According to the PIPC, Louis Vuitton's breach involved employee devices becoming infected with malware, which ultimately led to the compromise of information belonging to approximately 3.6 million individuals. Dior, another LVMH-owned brand, received a fine equivalent to more than $8.4 million after the personal data of 1.95 million individuals was exposed. The breach at Dior stemmed from an employee falling for a voice phishing attack. Tiffany was also penalized and ordered to pay approximately $1.6 million for exposing the details of roughly 4,600 people after also being victimized through a voice phishing attack.
The South Korean agency indicated that the data breaches were related to a SaaS platform intrusion, though it did not publicly name the platform involved. Louis Vuitton, Dior, and Tiffany were among dozens of major organizations targeted in a campaign aimed at Salesforce customers the previous year. The Scattered LAPSUS$ Hunters extortion group obtained millions of data records after gaining access to the Salesforce instances of the affected organizations. The hackers relied on social engineering tactics rather than exploiting vulnerabilities in Salesforce infrastructure or products. Voice phishing attacks and malware-infected employee devices were the specific intrusion vectors documented across the affected LVMH brands, enabling the threat actors to reach the Salesforce environment where large volumes of customer data were stored. The PIPC's regulatory action reflects the scale of the personal information exposed across the three brands and the failures in security controls that allowed the intrusions to succeed.
Sources
Sources available to members: 1 source.