Louis Vuitton, Dior, and Tiffany fined $25 million over data breaches
嗯,用户让我用中文总结一下这篇文章的内容,控制在一百个字以内,而且不需要用“文章内容总结”或者“这篇文章”这样的开头。直接写描述即可。 首先,我需要快速浏览一下文章内容。文章主要讲的是韩国对路易威登、迪奥和蒂芙尼这三个奢侈品牌进行了罚款,因为它们没有采取足够的安全措施,导致超过550万客户的个人信息被泄露。 接下来,我要提取关键信息:罚款金额是2500万美元,涉及的品牌属于LVMH集团,数据泄露是因为黑客入侵了他们的云客户管理系统。具体来说,路易威登是因为员工设备感染了恶意软件,迪奥是员工被钓鱼攻击,蒂芙尼则是语音钓鱼攻击。每个品牌的罚款金额分别是1640万、940万和185万美元。 然后,我需要把这些信息浓缩到100字以内。要注意用简洁的语言表达清楚主要事件和原因。 可能的结构是:韩国罚款三个奢侈品牌2500万美元,因为它们的数据安全措施不足导致客户信息泄露。然后简要提到每个品牌的情况和罚款金额。 检查一下是否符合要求:控制在100字以内,不使用特定的开头语句。看起来没问题。 </think> 韩国对路易威登、迪奥和蒂芙尼三家奢侈品牌处以2500万美元罚款,因其未采取足够数据安全措施,致超550万客户信息泄露。黑客通过云客户管理系统入侵,员工设备感染恶意软件或遭钓鱼攻击,导致数据泄露。三品牌分别被罚1640万、940万和185万美元。 2026-2-13 18:45:19 Author: www.bleepingcomputer.com(查看原文) 阅读量:1 收藏

Louis Vuitton, Dior, and Tiffany fined $25 million over data breaches

South Korea has fined luxury fashion brands Louis Vuitton, Christian Dior Couture, and Tiffany $25 million for failing to implement adequate security measures, which facilitated unauthorized access and the exposure of data belonging to more than 5.5 million customers.

All three brands are part of the Louis Vuitton Moët Hennessy (LVMH) group and suffered data breaches [1, 2, 3] after hackers gained access to their cloud-based customer management service.

The Personal Information Protection Commission (PIPC) in South Korea says that in the case of Louis Vuitton, an employee’s device was infected with malware, which led to compromising their software-as-a-service (SaaS) and leaking of data for 3.6 million customers.

Wiz

Although the product isn’t named, Google researchers linked the campaigns to the ShinyHunters gang, who targeted Salesforce platforms. The threat actor later claimed the breach of LVMH systems.

The breaches at the three regional brands last year exposed sensitive customer data, including names, phone numbers, email addresses, postal addresses, and purchase histories.

PIPC says that Louis Vuitton had been operating the SaaS tool since 2013, but "did not restrict access rights to Internet Protocol (IP) addresses, etc., and did not apply secure authentication methods when personal information handlers accessed the service from outside."

For failing to adequately secure access to customer data, the South Korean data protection agency imposed a $16.4 million fine on Louis Vuitton and ordered the company to announce the penalty on its business website.

At Dior, the breach occurred via a phishing attack on a customer service employee, who was tricked into granting the hacker access to the SaaS system, exposing data for 1.95 million customers.

Dior had been using the system since 2020, but didn’t implement allow-lists, didn’t place bulk data download restrictions, and failed to inspect access logs, delaying the discovery of the breach for over three months.

Additionally, Dior South Korea disclosed the breach to PIPC five days after learning about it. Under PIPA, organizations are required to notify the data protection agency within 72 hours from the time of becoming aware of a personal information leak.

Due to these violations, PIPC announced a $9.4 million financial penalty for Dior South Korea.

Tiffany was breached in a similar way, with attackers using voice phishing to trick a customer service employee into giving them access to the SaaS system. However, the impact was far lower in this case, with 4,600 clients exposed.

Similar to the other two cases, Tiffany also neglected to implement IP-based access controls and bulk data download restrictions and did not notify impacted individuals within the legally specified time frame. The brand received a $1.85 million fine.

PIPC emphasized that SaaS solutions do not exempt companies from their responsibility to securely manage client data, nor does it transfer that responsibility to the vendors of these solutions.

tines

The future of IT infrastructure is here

Modern IT infrastructure moves faster than manual workflows can handle.

In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.


文章来源: https://www.bleepingcomputer.com/news/security/louis-vuitton-dior-and-tiffany-fined-25-million-over-data-breaches/
如有侵权请联系:admin#unsafe.sh