Korea’s Personal Information Protection Commissioner fines 3 LVMH luxury brands after Salesforce data breaches
ID: 21e76781-563e-5b42-a291-f256c4283f45
STIX ID: report--21e76781-563e-5b42-a291-f256c4283f45
Feed Name: DataBreaches.Net
South Korea’s Personal Information Protection Commission fined LVMH’s Louis Vuitton Korea, Christian Dior Couture Korea, and Tiffany Korea after large-scale customer data leaks in 2025 tied to the ShinyHunters Salesforce campaign, where malware and social engineering enabled access to SaaS-based customer management systems. The regulator cited weak security controls—no IP allowlisting, lack of strong authentication, permissive bulk downloads, and inadequate log review—and delayed breach notifications, and ordered public disclosure of the penalties while emphasizing IP restrictions and strong multi-factor authentication for external access to personal data systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
