Cartier
Incident posture
Timeline
Summary
Cartier disclosed that attackers gained temporary access to its systems and obtained limited customer information including names, email addresses, and countries of residence. The company said no passwords, payment card details, or banking data were exposed, and it contained the breach, strengthened protections, notified law enforcement, and engaged an external cybersecurity firm to assist with remediation. Similar breaches have been reported at other luxury fashion brands, involving contact details and purchase histories but not payment credentials. The company said the stolen data could be used in targeted attacks.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Cartier disclosed a data breach after detecting unauthorized access to its systems, according to notification letters sent to customers and shared on social media. The company stated that an unauthorized party gained temporary access to its system and obtained limited client information. The compromised data included customers' names, email addresses, and the countries where they reside. Cartier emphasized that the breach did not expose more sensitive data such as passwords, credit card numbers, or banking details. The notification was issued on June 2, 2025, and the company said it had contained the issue and further enhanced the protection of its systems and data.
In response, Cartier informed law enforcement about the incident and engaged an external cybersecurity company to assist with remediation. The firm has been working with Cartier to investigate the breach and strengthen defenses. BleepingComputer attempted to obtain additional details from Cartier, such as the exact date of the breach and the number of individuals affected, but the company had not replied at the time of the article's publication. The disclosure follows a series of similar security incidents affecting other fashion brands, including Dior, Adidas, and Victoria's Secret, which also reported breaches involving customer contact information.
Cartier warned customers that the stolen names, email addresses, and country data could be used in targeted attacks and advised them to remain alert for unsolicited or suspicious communications. The company noted that, given the nature of the data, recipients should watch for any suspicious correspondence. No further details about the attack vector, threat actor identity, or specific systems compromised were provided in the source material. The narrative ends with the confirmation that Cartier is cooperating with authorities and external experts to address the breach.
Sources
Sources available to members: 1 source.