CSIDB logo
Incident

Kiabi

Incident posture

Attack window
Jan 2025
Location
France
Status
Unknown
CIA posture
Available to members
Updated
2026-01-23 10:06

Linked entities

Victim
Kiabi
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jan 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Kiabi's second-hand website suffered a credential stuffing attack where cybercriminals used compromised credentials from other breaches to access approximately 20,000 customer accounts. The attackers exfiltrated personal information including names, birth dates, postal addresses, and IBANs, though RIBs and identity documents stored with a third-party partner remained secure. In response, the company implemented IBAN masking, reset all customer passwords, and increased minimum password length to 14 characters to enhance security measures.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On January 7, 2025, Kiabi's second-hand e-commerce platform experienced a credential stuffing attack that compromised approximately 20,000 customer accounts. The company's security teams detected unauthorized access attempts where cybercriminals leveraged credentials obtained from prior third-party data breaches to systematically test millions of login combinations. This automated attack methodology succeeded in breaching accounts where customers had reused identical credentials across multiple platforms. Attackers exfiltrated personal data including full names, dates of birth, residential addresses, and International Bank Account Numbers (IBAN) from the compromised accounts. Kiabi confirmed that more sensitive financial documentation—specifically RIB bank details and identity documents—remained secure as they were stored externally by payment processor Lemonway and not accessible through the customer portal.

Following detection, Kiabi implemented immediate containment measures including IBAN masking functionality across all customer accounts and a forced password reset for all users of the second-hand platform. The company enhanced its password security policy by increasing the minimum character requirement to 14. Forensic analysis indicated the attackers operated at scale, consistent with industry patterns where credential stuffing attacks achieve approximately 0.1% success rates according to Cloudflare data. This incident mirrored a November 2024 attack against retailer Picard that exposed 45,000 customer records through similar methods. Kiabi's parent company, Mulliez Family Holdings, publicly disclosed the breach scope while emphasizing that core retail operations and primary e-commerce systems remained unaffected. The compromised second-hand platform maintained separate infrastructure from Kiabi's main retail websites.

Sources

Sources available to members: 1 source.

CSIDB