Three LVMH brands disclosed data breaches between May and July 2025. Christian Dior Couture reported a leak in May traced to a compromise dated to January. Louis Vuitton’s South Korea operation followed in early June, and its UK operation in early July.
The Group Structure Hides The Aggregate
Each disclosure was made by a brand, in a jurisdiction, under that jurisdiction’s rules, on its own timetable. That is legally correct and it is how conglomerates are supposed to work.
It also means no single notification described what a reader can see by lining them up: a sequence of compromises across entities under one owner, within ten weeks. The pattern exists only above the level at which anyone is obliged to report.
Which Is The Same Gap, From The Other Direction
Elsewhere this desk files the supplier problem — one compromised vendor generating dozens of downstream notifications, none of which names the shared cause. This is that structure inverted: a shared parent rather than a shared supplier, producing the same fragmentation.
In both cases the entity best placed to see the whole picture is not the entity carrying the reporting duty. Nobody is obliged to publish the sentence that connects them, so nobody does.
And A January Compromise Reported In May
The Dior timeline — access in January, disclosure in May — is a four-month gap of the kind filed at 26-0515 and 25-0210. It is worth noting without over-reading: discovery dates and access dates diverge for legitimate investigative reasons, and the material we reviewed does not establish when the compromise was found.
Compiled from public reporting, listed below. We have not established whether the three incidents share a cause, and we do not assert that they do. Corrections: corrections@forensicpost.com.