Fashion Box S.p.A.
Incident posture
Linked entities
- Victim
- Fashion Box S.p.A.
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Fashion Box S.p.A. disclosed that an unauthorized third party used a brute force method to breach its data center servers, compromising confidential information that may include personal data of employees and external stakeholders. The intrusion affected only the company’s own systems, leaving foreign subsidiaries untouched. Following detection, the firm reported the incident to Italian and European data protection authorities in Austria, France, Germany, the Netherlands, Spain, Sweden, Switzerland and the United Kingdom, informed its workforce, and implemented additional technical and organizational safeguards to prevent recurrence.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On 29 January 2025 the provider responsible for managing Fashion Box S.p.A.'s data center detected an unauthorized third‑party attack on the company's servers. The company announced that the intrusion had caused a loss of confidentiality of some information stored inside its corporate systems. According to the statement, the attack had taken place a month earlier, around December 2024, after a similar incident affected another firm referred to as Alf. The hackers gained entry by conducting a brute force attack that attempted to guess passwords, access credentials and cryptographic keys until the correct combination was found. This brute force effort succeeded in bypassing the security measures that had been implemented by the IT provider. The company specified that only its own servers were compromised, while the infrastructures of its foreign subsidiaries remained unaffected.
Based on the initial control activities launched by Fashion Box S.p.A., the compromised data included information saved in the company's computer systems that could relate to both corporate details and personal data of internal and external stakeholders. The company reported having already filed a complaint with the relevant judicial authorities and having notified the incident to data protection regulators in Italy and in several other countries where it operates, namely Austria, France, Germany, the Netherlands, Spain, Sweden, Switzerland and the United Kingdom. In parallel, Fashion Box S.p.A. informed its employees about the breach and promptly implemented technical and organisational measures aimed at strengthening its security posture and reducing the likelihood of similar events recurring. The company also published a communication on its website describing what had occurred. No further details about the exact volume or type of data exfiltrated were disclosed in the source material. The narrative ends here.
Sources
Sources available to members: 1 source.