Tiffany & Co. discloses South Korean customer data breach at third-party platform
- Organization
- Tiffany & Co.
- Exploit
- Third-Party Data Breach
- Industry
- Retail
Tiffany & Co. notified customers in South Korea in late May 2025 that their personal information had been exposed in a security incident affecting a third-party application used to manage global customer records. The jeweller, which is owned by LVMH, said the unauthorized access took place on 8 April 2025 and that it verified on 9 May that data belonging to South Korean customers was involved.
Email notices went to affected customers on 26 May. Teiss reported that the exposed fields covered names, postal addresses, telephone numbers, email addresses, internal customer identification numbers and purchase history. The company said financial information and payment card details were not part of the compromised dataset.
A company representative described the trigger as suspicious activity detected on a third-party application managing global customer data. Tiffany did not publish a figure for the number of people notified at the time.
The disclosure came weeks after a comparable incident at Dior, another LVMH brand, which had also told South Korean customers that contact details and purchase records were accessed. South Korea's Personal Information Protection Commission later concluded that the Tiffany incident stemmed from a voice phishing attack on an employee and affected roughly 4,600 people, and in February 2026 fined the company about $1.6 million.