Skip to content
NetarxImpact Database
Vishing (Voice Phishing)No AI reportedReported

Kering confirms Gucci, Balenciaga and Alexander McQueen customer data theft

Kering (Gucci, Balenciaga, Alexander McQueen) · Retail · France · September 2025

What happened

Luxury group Kering confirmed in September 2025 that customer data from Gucci, Balenciaga and Alexander McQueen had been stolen earlier in the year. Names, email addresses, phone numbers, physical addresses and total spend were exposed; Kering said no payment card or bank data was taken. ShinyHunters claimed to hold roughly 7.4 million email addresses and said Kering refused to pay a ransom.

How the deception worked

ShinyHunters told reporters the access came from the same telephone-based playbook it ran against dozens of consumer brands in 2025: a caller posing as internal IT or a SaaS vendor contacted staff with CRM access, cited a plausible support ticket, and guided them through granting a connected application permission in the customer-relationship platform. The identity impersonated was the victim's own IT function; the trust signal abused was a vendor-branded consent page that looked routine. No malware was deployed. Once approved by a human, the app was used to enumerate and export customer profiles, which were then used for private extortion demands.

The control that would have caught it· our reading, not a claim from the sources

Retail and luxury CRM tenants should treat third-party app consent as a privileged administrative action requiring a second approver and out-of-band caller verification.

Sources (2)

  1. Company that owns Gucci, Balenciaga, other brands confirms hack
    TechCrunch·techcrunch.comOpen ↗
  2. Gucci, Balenciaga, McQueen confirm breach, ShinyHunters claim 7.4M customers' data stolen
    Cybernews·cybernews.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.