- Dior confirmed to lose sensitive customer data
- Passwords and payment data were not taken
- No groups assumed the responsibility yet
Global Fashion Powerhouse Dior confirmed to suffer a cyberattack where sensitive customer information was lost. Payment data, bank account or credit card information was not taken.
In a statement shared with Bleeping computerDior said it is currently investigating the incident and that it brought third-party cybersecurity experts to help:
“House of Dior recently discovered that an unauthorized external party was given access to some of the data we have for our Dior Fashion and Accessory customers,” the spokesman told the publication. “We immediately took steps to contain this incident. The teams of Dior, supported by leading cyber security experts, continue to investigate and respond to the incident.”
Names and addresses
While Dior confirmed that passwords and payment information were not accessed, it did not say how many people were affected or what kind of information was taken. Bleeping computer Claims to have found screenshots of data violation notification -e emails sent to Chinese customers who share a little more insight.
Apparently, the attack was discovered on May 7, when Miscreants went away with people’s full names, gender information, phone numbers, e -mail addresses, postal addresses and purchase history.
This is more than enough data to create personalized, compelling phishing -e emails and get Dior customers to share their passwords or make unwanted purchases.
This also seems to have been an international incident, as at least Korean and Chinese customers appear to have been affected. In South Korea, Dior could face a lawsuit in order not to notify relevant authorities.
Currently, no threat actors have taken responsibility for the attack and the stolen data has not appeared on the dark web.
Dior is a French multinational luxury goods company headquartered in Paris. The company designs and sells advanced fashion and operates globally and has a significant presence in Europe, Asia and North America. In 2023, the company reported a $ 96.60 billion revenue.
Via Bleeping computer