South Korea’s Personal Information Protection Commission (PIPC) fined the Korean subsidiaries of Louis Vuitton, Christian Dior Couture, and Tiffany a combined KRW 36.033 billion (~$25M), with additional penalties, after customer data was exposed through unauthorized access to a cloud-based customer management SaaS platform widely reported as Salesforce. The incidents were linked by multiple reports to the ShinyHunters campaign targeting Salesforce environments, and the regulator ordered the companies to publicly post notice of the sanctions on their websites.
PIPC attributed the Louis Vuitton breach to malware on an employee device that enabled theft of SaaS credentials, leading to exposure of data for about 3.6 million individuals across multiple incidents; the regulator cited missing IP-based access restrictions and lack of strong authentication for external access. For Dior and Tiffany, PIPC described voice phishing (vishing)/social engineering of customer service staff that resulted in attackers being granted SaaS access, exposing data for about 1.95 million (Dior) and ~4,600 (Tiffany) individuals; cited control gaps included lack of IP restrictions, insufficient limits on bulk export/download tools, and inadequate log review, and both Dior and Tiffany were also faulted for missing the statutory 72-hour breach notification window. Exposed data was reported to include customer identifiers and contact details (e.g., names, phone numbers, emails, addresses) and purchase history.

See the reporting duties and controls this puts on the clock.
7 events from the most recent confirmed update back to the earliest known activity.
On February 13, 2026, South Korea's Personal Information Protection Commission fined Louis Vuitton Korea, Christian Dior Couture Korea, and Tiffany Korea a combined roughly $25 million (about 36 billion won) for data breaches affecting more than 5.5 million customers. The regulator cited missing IP restrictions, weak authentication, inadequate monitoring and download controls, and ordered the companies to post notices of the fines on their websites.
Reporting and regulator summaries connected the luxury-brand breaches to the ShinyHunters campaign targeting Salesforce environments. The threat actor was also reported to have claimed the LVMH breach.
After recognizing their breaches, both Christian Dior Couture Korea and Tiffany Korea failed to notify authorities within the statutory 72-hour window. Regulators later cited the delayed notifications as separate compliance violations.
Tiffany Korea was also compromised through voice phishing of customer service staff, enabling unauthorized access and bulk downloads from its customer management SaaS. The incident exposed personal data of about 4,600 individuals.
Christian Dior Couture Korea was compromised after customer service representatives were targeted with social engineering and voice phishing, allowing attackers to provision or grant access to the SaaS system. The breach exposed data for about 1.95 million individuals and reportedly went undetected for more than three months.
In mid-June 2025, unauthorized access to Louis Vuitton Korea's SaaS environment led to three leak events exposing personal data of about 3.6 million individuals. Exposed information included customer contact details and related personal data.
Malware on a Louis Vuitton Korea employee device enabled attackers to steal credentials for a cloud-based customer management SaaS platform, setting up the later data exposure. The incident was later linked by reporting to the broader ShinyHunters Salesforce-focused campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
databreaches.net
Open sourcecsoonline.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.