What happened
Three LVMH houses, Louis Vuitton, Christian Dior and Tiffany & Co., disclosed customer data breaches during 2025 that BleepingComputer and other outlets tied to the ShinyHunters Salesforce campaign. Exposed data was customer contact information and purchase-related details rather than payment card data. The brands notified customers in several countries as the intrusions came to light across May to July 2025.
How the deception worked
The operators impersonated internal IT support in telephone calls to employees with CRM access, then directed them to Salesforce's connected-app setup page and had them enter a connection code that bound a malicious OAuth application, in some cases renamed 'My Ticket Portal', to the tenant. Separately the group hosted fake Okta sign-in pages to capture credentials and MFA tokens from staff who were talked into visiting them. The trust signals abused were a company-branded login page and a helpful-sounding colleague; the pressure was a support ticket that needed closing. The authorised app then exported customer records for extortion.
The control that would have caught it· our reading, not a claim from the sources
Phishing-resistant MFA plus a hard block on user-consented OAuth applications would have defeated both halves of this technique.
Sources (2)
- ShinyHunters behind Salesforce data theft attacks at Qantas, Allianz Life, and LVMHBleepingComputer·bleepingcomputer.comOpen ↗
- Louis Vuitton, Dior, and Tiffany fined $25 million over data breachesBleepingComputer·bleepingcomputer.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.