Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Dior, Louis Vuitton, Tiffany Fined $25 Million in South Korea After Data Breaches

Luxury brands were among the dozens of major companies whose Salesforce instances were targeted by Scattered LAPSUS$ Hunters.

Dior data breach

South Korea’s Personal Information Protection Commission (PIPC) announced last week that it has issued significant fines to several major luxury brands over a recent hacker attack that resulted in massive data breaches. 

The fines, totaling 36 billion Korean won ($25 million), were imposed on Louis Vuitton, Dior, and Tiffany, all owned by the Paris-based multinational luxury goods conglomerate LVMH.

According to the Korean regulator, Louis Vuitton received a fine of roughly $15 million for cybersecurity failures that involved employee devices getting infected with malware and the information of approximately 3.6 million individuals getting compromised. 

Dior was fined the equivalent of more than $8.4 million for exposing the information of 1.95 million individuals after an employee fell for a voice phishing attack. 

Tiffany has been ordered to pay $1.6 million for exposing the details of roughly 4,600 people after also falling victim to a voice phishing attack. 

The South Korean agency said the data breaches are related to a SaaS platform intrusion, but did not name the platform.

Advertisement. Scroll to continue reading.

However, Louis Vuitton, Dior, and Tiffany were among the dozens of major organizations hit last year in a campaign targeting Salesforce customers.

The Scattered LAPSUS$ Hunters extortion group obtained millions of data records after gaining access to the Salesforce instances of the targeted organizations. The hackers leveraged social engineering rather than vulnerabilities in Salesforce infrastructure or products.

SecurityWeek has contacted LVMH for comment and will update this article if the company responds.

Related: Flickr Security Incident Tied to Third-Party Email System

Related: Dutch Carrier Odido Discloses Data Breach Impacting 6 Million

Related: Conduent Breach Hits Volvo Group: Nearly 17,000 Employees’ Data Exposed

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Dali Rajic is joining OpenAI as Chief Revenue Officer.

Erika Dean has been appointed Chief Information Security Officer at Tricentis.

C1 has named Jeff St. Clair Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.