Skip to content
NetarxImpact Database
Vishing (Voice Phishing)No AI reportedReported

LVMH brands Louis Vuitton, Dior and Tiffany hit in Salesforce data-theft wave

LVMH (Louis Vuitton, Christian Dior, Tiffany & Co.) · Retail · France · July 2025

What happened

Three LVMH houses, Louis Vuitton, Christian Dior and Tiffany & Co., disclosed customer data breaches during 2025 that BleepingComputer and other outlets tied to the ShinyHunters Salesforce campaign. Exposed data was customer contact information and purchase-related details rather than payment card data. The brands notified customers in several countries as the intrusions came to light across May to July 2025.

How the deception worked

The operators impersonated internal IT support in telephone calls to employees with CRM access, then directed them to Salesforce's connected-app setup page and had them enter a connection code that bound a malicious OAuth application, in some cases renamed 'My Ticket Portal', to the tenant. Separately the group hosted fake Okta sign-in pages to capture credentials and MFA tokens from staff who were talked into visiting them. The trust signals abused were a company-branded login page and a helpful-sounding colleague; the pressure was a support ticket that needed closing. The authorised app then exported customer records for extortion.

The control that would have caught it· our reading, not a claim from the sources

Phishing-resistant MFA plus a hard block on user-consented OAuth applications would have defeated both halves of this technique.

Sources (2)

  1. ShinyHunters behind Salesforce data theft attacks at Qantas, Allianz Life, and LVMH
    BleepingComputer·bleepingcomputer.comOpen ↗
  2. Louis Vuitton, Dior, and Tiffany fined $25 million over data breaches
    BleepingComputer·bleepingcomputer.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.