Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Data Breach - The Devil Wears Data: Dior Admits to Customer Data Leak in China
Data Breach Attacks Data Loss Prevention Data Protection Latest News News & Analysis

The Devil Wears Data: Dior Admits to Customer Data Leak in China

Kirsten DoyleBy Kirsten DoyleMay 15, 20255 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Dior Admits to Customer Data Leak
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Luxury fashion brand Dior has alerted customers to a data breach involving its Chinese customer database. The company revealed that an unauthorised external party had gained access to sensitive customer information, though financial data was not affected. 

The breach came to light after Dior sent an internal memo to affected consumers on 13 May. According to multiple Chinese media outlets, including Global Times, the memo stated that the company discovered the breach on 7 May.  

The compromised data includes customer names, gender, phone numbers, email addresses, mailing addresses, purchase histories, shopping preferences, and other user-related information collected by Dior. 

In a statement, the fashion giant said: “We recently identified a security breach that resulted in unauthorized access to certain data we hold, including customer information. Upon discovering the issue, we immediately took steps to contain it.” 

While Dior has not disclosed the number of individuals impacted, it clarified that no financial information (bank account numbers, IBANs, or credit card details) was compromised. The memo was reportedly only sent to customers directly affected by the incident. 

In the aftermath of the incident, Dior urged Chinese customers to be careful, and advised against responding to suspicious messages, emails, or calls. It also warned customers not to share verification codes or personal credentials with unknown sources.  

Responding to public concern, a Dior customer service representative confirmed the incident, and said upon discovering the issue, they immediately took steps to contain it, and that the matter is still under investigation. Customers with inquiries will be updated directly via phone if new information becomes available. 

The breach comes at a challenging time for Dior’s parent company, LVMH. The French luxury conglomerate reported a 3% year-over-year decline in group revenue for the first quarter of 2025, with earnings totaling €20.3 billion. Revenue from China, excluding Japan, fell by 11%, and the region’s contribution to LVMH’s overall sales dropped from 33% in 2024 to 30% this year.  

Be on High Alert 

Muhammad Yahya Patel, Global Security Evangelist & Advisor, Office of the CTO, at Check Point Software, said: “In the wake of the Dior data breach, customers should be on high alert for phishing emails. These might appear to come from Dior and could include password reset requests, contact detail updates, or fake purchase confirmations, all of which are common tactics used by cybercriminals to trick victims into clicking malicious links.” 

Patel said tiven that Dior is a luxury shopping brand, there’s also a heightened risk of scammers pushing fake promotions, discount codes, or exclusive sale offers to lure unsuspecting customers.  

“Anyone who’s interacted with the brand recently should treat any unexpected email or SMS with caution and avoid clicking on links or entering login details via third-party websites. In today’s digital world, it’s always safer to visit a brand’s official website directly through your web browser rather than clicking on links in emails or SMS messages. Anyone who’s interacted with the brand recently should treat any unexpected communication with caution and avoid entering login details or payment information unless they’re certain it’s legitimate.”  

Ambiguity About the True Extent 

Javvad Malik, Lead Security Awareness Advocate at KnowBe4, adds that the fashion house’s disclosure, while prompt, employs carefully measured language regarding the scope of affected data. “This careful phrasing, “some of the data we hold”, leaves considerable ambiguity about the true extent of the compromise, which is problematic from a transparency standpoint.” 

Malik says although the non-exposure of payment information and credentials provides some reassurance, the compromised personal data (names, contact details, purchase history) presents substantial risk. ”This combination of information creates a perfect foundation for highly targeted social engineering attacks against a particularly affluent customer base.” 

The international dimension of this breach, affecting customers across multiple jurisdictions including South Korea and China, also introduces complex regulatory compliance challenges, Malik adds. “The reports from Korean media suggesting potential notification failures are particularly concerning, as timely and comprehensive regulatory notification has been a well-established compliance requirement for years.” 

Retailers in the Crosshairs 

“Dior joins a long line of big-name retailers who’ve been hit in the past few weeks, signifying a concerted effort on the part of cybercriminals to target them,” comments Jamie Akhtar, CEO and Co-founder at CyberSmart. “The manner of attack and the kinds of data stolen bear remarkable similarities to other recent attacks on major retailers, confirming that, more than disruption, cybercriminals are after information.”

Akhtar says this type of data can be sold on the dark web quite lucratively for a quick buck or used to launch all manner of phishing and ransomware campaigns (or both for particularly enterprising hackers).  

“What’s concerning is the regularity with which these kinds of attacks seem to be successfully launched against retailers, suggesting that the industry needs to take a serious look at its security measures. No financial data was stolen this time, however, the data that was stolen can still be used to target Dior customers. What’s more, the next retailer to be hit might not be so lucky,” Akhtar adds.  

Truly Borderless Crime 

“On a global scale, the retail industry has recently seen cyber-attacks that further attribute to millions of dollars of losses for major retailers as well as associated banks, manufacturers, and other supporting supply chain economies,” says Aditi Gupta, Senior Manager at Black Duck. 

“The recent attack on Dior in China and M&S and Coop breaches in UK has made cybercrime truly borderless and a major threat to the direct consumer world, Gupta adds. “While the details unfold for the Dior attacks in China, it is prudent for consumers to be wary of any suspicious messages, calls or emails regarding recent purchases or discount codes.” 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
  • Kirsten Doyle
    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day
  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

7-Eleven Notifies Franchise Applicants After Breach Exposes Personal Data

May 19, 20262 Mins Read

Canvas cyberattack disrupts universities as ShinyHunters threatens massive data leak

May 12, 20267 Mins Read

Zara Owner Inditex Confirms Customer Data Breach Affecting Nearly 200,000 People

May 11, 20263 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}