Kathmandu Holdings
| Primary URL | Location | Industry | www[.]kathmanduholdings[.]com |
Country
New Zealand
|
Retail
|
|---|
Profile
Kathmandu Holdings operates as a retailer that specializes in outdoor clothing, footwear, and equipment for consumers engaged in activities such as hiking, camping, and travel. The company maintains a network of physical store locations alongside an online store platform, allowing customers to purchase products through both brick‑and‑mortar and digital channels. Its core merchandise includes technical apparel, insulated jackets, hiking boots, backpacks, and various accessories designed for outdoor pursuits. Based on the regulatory notifications issued after the 2019 security incident, Kathmandu serves customers in New Zealand, Australia, and the United Kingdom, indicating that its market reach spans at least these three countries. The business model emphasizes providing gear suited to varied climates and terrains, catering to both recreational enthusiasts and more serious adventurers. The company’s online platform was the specific vector through which unauthorized third‑party access occurred in early 2019, while its physical stores were reported to remain unaffected by the breach.
Kathmandu Holdings is headquartered in New Zealand, reflecting its origins as a locally grown retailer that has expanded internationally. A distinguishing attribute of the organisation is its focus on the outdoor recreation sector, positioning it as a specialist provider rather than a general‑purpose apparel retailer. The firm’s omnichannel approach—combining physical retail outlets with an e‑commerce site—enables it to meet consumer preferences for both in‑person try‑on and online convenience. In response to the 2019 data breach, Kathmandu engaged external cybersecurity experts to investigate the intrusion, secured its systems promptly, and notified affected customers directly. The incident triggered formal notifications to privacy authorities in Australia, New Zealand, and the United Kingdom, as well as reports to cybercrime units and police, demonstrating a multi‑jurisdictional compliance response. The company publicly apologized for the potential harm to customers and reiterated its commitment to data protection, highlighting a proactive stance on safeguarding personal information following the event.
