Skip to content
NetarxImpact Database
Vishing (Voice Phishing)No AI reportedReported

Chanel notifies US clients after third-party client-care database breach

Chanel · Retail · United States · August 2025

What happened

Chanel told US clients in August 2025 that a database hosted by a third-party service provider and used by its client-care team had been accessed without authorisation. Names, email addresses, mailing addresses and phone numbers were exposed. Chanel said no payment card, bank or government identification data was involved. Trade and security press linked the incident to the ShinyHunters Salesforce campaign.

How the deception worked

Chanel described the breach as affecting a third-party-hosted client-care database and did not name the entry technique, so the social-engineering attribution rests on reporting about the campaign. In that pattern, attackers telephoned staff who administer or use the CRM, posed as the company's IT support or the platform vendor, and asked them to authorise a connected application under the cover of a routine tooling change. The consent screen came from the genuine SaaS provider, which made the request look legitimate to the employee. Once authorised, the application could read and export the client database at volume with no further human involvement.

The control that would have caught it· our reading, not a claim from the sources

Client-care platforms holding VIP customer data should disable end-user OAuth consent entirely and require verified, ticketed approval for any new integration.

Sources (2)

  1. Chanel Alerts Client of Third-Party Breach
    Dark Reading·darkreading.comOpen ↗
  2. Third-Party Data Breach Hits Luxury Fashion Retailers Chanel and Pandora
    CPO Magazine·cpomagazine.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.