Cartier tells clients names and email addresses were stolen in system breach
- Organization
- Cartier
- Exploit
- Hacking
- Industry
- Retail
Cartier, the luxury jewelry house owned by Richemont, emailed clients in early June 2025 to say an unauthorized party had gained temporary access to its systems and obtained a limited amount of client information.
The company said the exposed data was confined to names, email addresses and the country in which the client was based. It stated that no passwords, credit card numbers or other banking information were involved, and it advised recipients to stay alert for unsolicited or suspicious communications that might attempt to use the stolen details for phishing.
Cartier said it had contained the issue and further enhanced the protection of its systems and data, had informed the relevant authorities, and was working with external cybersecurity specialists on the investigation. It did not disclose how many clients were affected, when the intrusion took place, or how the attacker got in.
The disclosure came during a run of intrusions at consumer and luxury brands. Coverage at the time placed it alongside incidents at Victoria's Secret, Adidas and Dior, and against the wider backdrop of ransomware attacks on major UK retailers. No threat group publicly claimed the Cartier breach and the company did not attribute it to anyone.