{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-lvmh-brands-louis-vuitton-dior-and-tiffany-hit-in-salesforce-data-theft"},"incident":{"slug":"2025-lvmh-brands-louis-vuitton-dior-and-tiffany-hit-in-salesforce-data-theft","title":"LVMH brands Louis Vuitton, Dior and Tiffany hit in Salesforce data-theft wave","date":"2025-07","date_precision":"month","year":2025,"victim_org":"LVMH (Louis Vuitton, Christian Dior, Tiffany & Co.)","sector":"Retail","country":"France","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"ShinyHunters / UNC6040","summary":"Three LVMH houses, Louis Vuitton, Christian Dior and Tiffany & Co., disclosed customer data breaches during 2025 that BleepingComputer and other outlets tied to the ShinyHunters Salesforce campaign. Exposed data was customer contact information and purchase-related details rather than payment card data. The brands notified customers in several countries as the intrusions came to light across May to July 2025.","how_it_worked":"The operators impersonated internal IT support in telephone calls to employees with CRM access, then directed them to Salesforce's connected-app setup page and had them enter a connection code that bound a malicious OAuth application, in some cases renamed 'My Ticket Portal', to the tenant. Separately the group hosted fake Okta sign-in pages to capture credentials and MFA tokens from staff who were talked into visiting them. The trust signals abused were a company-branded login page and a helpful-sounding colleague; the pressure was a support ticket that needed closing. The authorised app then exported customer records for extortion.","lessons":"Phishing-resistant MFA plus a hard block on user-consented OAuth applications would have defeated both halves of this technique.","confidence":"Reported","sources":[{"title":"ShinyHunters behind Salesforce data theft attacks at Qantas, Allianz Life, and LVMH","url":"https://www.bleepingcomputer.com/news/security/shinyhunters-behind-salesforce-data-theft-attacks-at-qantas-allianz-life-and-lvmh/","publisher":"BleepingComputer"},{"title":"Louis Vuitton, Dior, and Tiffany fined $25 million over data breaches","url":"https://www.bleepingcomputer.com/news/security/louis-vuitton-dior-and-tiffany-fined-25-million-over-data-breaches/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-lvmh-brands-louis-vuitton-dior-and-tiffany-hit-in-salesforce-data-theft"}}