Desk live·
ForensicPost
Breaches/Retail/File 25-0710

Three LVMH Brands Disclosed Separate Breaches Between May and July

Between May and July 2025, three LVMH brands disclosed separate breaches: Dior, then Louis Vuitton in South Korea, then Louis Vuitton in the UK. Each was reported on its own terms.

Constructed geometry · not a chart of case data
TargetLVMH brands
ActorUnattributed
D. Kennedy11 min readConfidence: medium2 sources reviewed

Three LVMH brands disclosed data breaches between May and July 2025. Christian Dior Couture reported a leak in May traced to a compromise dated to January. Louis Vuitton’s South Korea operation followed in early June, and its UK operation in early July.

The Group Structure Hides The Aggregate

Each disclosure was made by a brand, in a jurisdiction, under that jurisdiction’s rules, on its own timetable. That is legally correct and it is how conglomerates are supposed to work.

It also means no single notification described what a reader can see by lining them up: a sequence of compromises across entities under one owner, within ten weeks. The pattern exists only above the level at which anyone is obliged to report.

Which Is The Same Gap, From The Other Direction

Elsewhere this desk files the supplier problem — one compromised vendor generating dozens of downstream notifications, none of which names the shared cause. This is that structure inverted: a shared parent rather than a shared supplier, producing the same fragmentation.

In both cases the entity best placed to see the whole picture is not the entity carrying the reporting duty. Nobody is obliged to publish the sentence that connects them, so nobody does.

And A January Compromise Reported In May

The Dior timeline — access in January, disclosure in May — is a four-month gap of the kind filed at 26-0515 and 25-0210. It is worth noting without over-reading: discovery dates and access dates diverge for legitimate investigative reasons, and the material we reviewed does not establish when the compromise was found.

How we reported this

Compiled from public reporting, listed below. We have not established whether the three incidents share a cause, and we do not assert that they do. Corrections: corrections@forensicpost.com.

Sources
  1. Luxury brand Louis Vuitton suffers a multi-country cyber attack that leaked personal dataCPO Magazine
  2. Luxury brands under siege: the 2025 cyberattack wave targeting high-end retailBreached.Company
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary