Cartier latest luxury brand hit by consumer data breach

Cartier luxury watches are displayed in a store window on Fifth Avenue in New York, April 8. AFP-Yonhap
Luxury jewelry brand Cartier has confirmed a breach of customer data, raising concerns over data security among high-end brands following recent incidents involving Dior and Tiffany.
The company sent out an email Tuesday informing its customers that an “unauthorized third party” accessed its systems temporarily and obtained certain customer information.
While Cartier assured customers that sensitive financial data such as passwords, credit card numbers and bank account information were not compromised, the brand said it has confirmed that the compromised data possibly includes customer names, email addresses, birth dates and country of residence.
An email sent by Cartier informing its customers of a breach in their personal information / Captured from X
The company noted that it has taken immediate action to strengthen its security systems and is working closely with external cybersecurity experts and relevant authorities to investigate the incident.
The Cartier announcement comes as Korea's Personal Information Protection Commission (PIPC) is currently conducting an investigation into data breaches at Christian Dior and Tiffany, both owned by the French luxury conglomerate LVMH.
According to the PIPC, Dior discovered its data breach on May 7 — four months after it occurred in January — and reported it to the commission on May 10. Tiffany detected its breach in April, confirmed the issue on May 9 and submitted its report on May 22.
The commission will launch an investigation to determine the exact number of individuals affected, the extent of the data leak and whether the companies violated Korea’s personal data protection regulations.
Both companies were using cloud-based software, software as a service (SaaS), for the customer management system. The initial findings suggest that the attacker accessed the service using credentials from employees’ accounts. The commission will also examine the security status of the SaaS platform itself.
The PIPC will also look into the companies’ delay in reporting the breaches, both to the commission and to its customers.
According to the Personal Information Protection Act, any organization handling personal data of more than 1,000 individuals is required to report a breach to the PIPC within 72 hours after acknowledging it.
The commission emphasized the importance of multi-factor authentication, assessing internet protocol accesses and stricter staff training to prevent account hacking and phishing attacks. It also called on companies using SaaS platforms to implement robust access controls and monitor for suspicious activity.