logo

Korea’s Personal Information Protection Commissioner fines 3 LVMH luxury brands after Salesforce data breaches

ID: 21e76781-563e-5b42-a291-f256c4283f45

STIX ID: report--21e76781-563e-5b42-a291-f256c4283f45

Feed Name: DataBreaches.Net

Threat Score
76/100

Date Published: 2026-02-13

Date Updated: 2026-04-19

Author: Dissent

...
...

South Korea’s Personal Information Protection Commission fined LVMH’s Louis Vuitton Korea, Christian Dior Couture Korea, and Tiffany Korea after large-scale customer data leaks in 2025 tied to the ShinyHunters Salesforce campaign, where malware and social engineering enabled access to SaaS-based customer management systems. The regulator cited weak security controls—no IP allowlisting, lack of strong authentication, permissive bulk downloads, and inadequate log review—and delayed breach notifications, and ordered public disclosure of the penalties while emphasizing IP restrictions and strong multi-factor authentication for external access to personal data systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.