Cartier notified customers in mid-2025 that an unauthorised party had accessed its systems and obtained names, email addresses and countries of residence. No payment details or passwords were reported taken.
The Standard Reassurance Does Not Hold Here
The customary line — limited fields, no financial data, low risk — is usually defensible. It is not defensible for a luxury jeweller, because the field that matters is not in the list of fields taken. It is membership of the list itself.
A name on a Cartier customer file asserts something no individual data element does: this person buys expensive, portable, resaleable goods. As a targeting list for high-value phishing, for physical burglary, or for the impersonation of the retailer itself, it is close to ideal — and none of that requires a single additional field.
A Pattern This Database Keeps Recording
The same inversion appears at 26-0326, where a utility’s consumption data reveals when a house is empty, and at 26-0617, where a cardiac monitor produces a continuous record of a person. In each case the sensitivity is in what holding the record implies, not in the record’s contents.
Data-protection assessments enumerate fields. They have no column for the inference that follows from the identity of the controller, which means the risk that matters most here is the one the assessment cannot express.
Compiled from public reporting, listed below. Affected volume was not disclosed in the material we reviewed and we do not estimate it. Corrections: corrections@forensicpost.com.