Christian Dior Couture confirms customer data breach affecting Asian shoppers
- Organization
- Christian Dior Couture
- Exploit
- Phishing
- Industry
- Retail
Christian Dior Couture, the fashion house owned by LVMH, confirmed in mid-May 2025 that an unauthorized external party had reached a database holding customer records. Infosecurity Magazine reported that the company detected the intrusion on 7 May 2025 and did not say when the access began. Bloomberg reported that Le Monde had placed the attack in January 2025 and had said Asian customers were notified that week, and that a Dior representative did not confirm those details.
The records belonged to customers of the Dior Fashion and Accessories business. According to the notifications, the exposed fields included full names, gender, telephone numbers, email addresses, postal addresses and information about purchase amounts and shopping preferences. Dior said no bank details, IBANs, credit card numbers or account passwords were held in the affected database.
Reporting at the time indicated that clients in South Korea and China were the first to be told, with Dior sending breach notices by text message. The company did not publish a figure for the number of people affected.
Dior said it moved to contain the incident on discovery, engaged outside cybersecurity specialists and notified the relevant regulatory authorities. It advised recipients to watch for phishing messages referencing the brand. South Korean authorities began examining whether the company had met local notification requirements, and no group had claimed responsibility as of late May 2025.