{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-kering-confirms-gucci-balenciaga-and-alexander-mcqueen-customer-data-the"},"incident":{"slug":"2025-kering-confirms-gucci-balenciaga-and-alexander-mcqueen-customer-data-the","title":"Kering confirms Gucci, Balenciaga and Alexander McQueen customer data theft","date":"2025-09","date_precision":"month","year":2025,"victim_org":"Kering (Gucci, Balenciaga, Alexander McQueen)","sector":"Retail","country":"France","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters","summary":"Luxury group Kering confirmed in September 2025 that customer data from Gucci, Balenciaga and Alexander McQueen had been stolen earlier in the year. Names, email addresses, phone numbers, physical addresses and total spend were exposed; Kering said no payment card or bank data was taken. ShinyHunters claimed to hold roughly 7.4 million email addresses and said Kering refused to pay a ransom.","how_it_worked":"ShinyHunters told reporters the access came from the same telephone-based playbook it ran against dozens of consumer brands in 2025: a caller posing as internal IT or a SaaS vendor contacted staff with CRM access, cited a plausible support ticket, and guided them through granting a connected application permission in the customer-relationship platform. The identity impersonated was the victim's own IT function; the trust signal abused was a vendor-branded consent page that looked routine. No malware was deployed. Once approved by a human, the app was used to enumerate and export customer profiles, which were then used for private extortion demands.","lessons":"Retail and luxury CRM tenants should treat third-party app consent as a privileged administrative action requiring a second approver and out-of-band caller verification.","confidence":"Reported","sources":[{"title":"Company that owns Gucci, Balenciaga, other brands confirms hack","url":"https://techcrunch.com/2025/09/15/company-that-owns-gucci-balenciaga-other-brands-confirms-hack","publisher":"TechCrunch"},{"title":"Gucci, Balenciaga, McQueen confirm breach, ShinyHunters claim 7.4M customers' data stolen","url":"https://cybernews.com/news/gucci-balenciaga-kering-data-breach-7-million-customers-compromised-shiny-hunters/","publisher":"Cybernews"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-kering-confirms-gucci-balenciaga-and-alexander-mcqueen-customer-data-the"}}