Hackers Steal Millions of Customer Records from Gucci, Balenciaga and Other Kering Brands

Cybersecurity experts warn that the breach puts high-net-worth customers at risk of phishing attempts and other scams.

1 min read
Gucci

Millions of personal records belonging to customers of luxury fashion brands Gucci, Balenciaga, Brioni, and Alexander McQueen have been stolen in a series of cyberattacks, according to reports. The breaches were allegedly carried out by the cybercriminal group ShinyHunters.

The stolen data includes names, contact details, addresses, birth dates, and purchase histories, but Kering, the French conglomerate that owns the brands, confirmed that no financial information — such as credit card numbers or government-issued IDs — was compromised.

Kering discovered the breach in June and has since informed authorities and notified affected customers. The Information Commissioner’s Office, however, said it had not been formally alerted to the incident.

According to reports, ShinyHunters claimed to have stolen 56 million customer records across two attacks: one targeting Gucci last year and another in April this year affecting the other brands. The group reportedly attempted to extort Balenciaga for €750,000 in bitcoin to return the data, but negotiations collapsed, according to DataBreaches.net, which published alleged transcripts of the discussions.

A ShinyHunters hacker told the BBC that 7.4 million unique email addresses were affected. The group, active since 2020 and also known as ShinyCorp, recently announced a merger with another cybercriminal organization, Scattered Spider, and has promoted its hacks through a dedicated Telegram channel.

Four individuals suspected of involvement with ShinyHunters were arrested in France in June over unrelated cyberattacks on an electronics retailer, a telecoms company, and the French Football Federation.

Cybersecurity experts warn that the breach puts high-net-worth customers at risk of phishing attempts and other scams. Ade Clewlow, senior adviser at NCC Group, said: “High-net-worth individuals face significant risk after Kering’s data breach exposed detailed records… Customers should be hyper-vigilant to attempts to steal personal information or online credentials.”

The attacks on Kering follow a wave of cyber intrusions affecting other luxury and retail brands this year, including Marks & Spencer, Co-Op, Harrods, Cartier, and Louis Vuitton.

Kering emphasized that the breach was identified promptly and that measures have been taken to secure its systems. “Our houses immediately disclosed the breach to the relevant authorities and notified customers according to local regulations,” the company said.

Sri Lanka Guardian

The Sri Lanka Guardian is an online web portal founded in August 2007 by a group of concerned Sri Lankan citizens including journalists, activists, academics and retired civil servants. We are independent and non-profit. Email: editor@slguardian.org

Leave a Reply

Your email address will not be published.

Latest from Blog