Particle.news

Download on the App Store

Dior Faces Legal Scrutiny Over Reporting Lapses in Data Breach Impacting South Korea and China

The luxury brand failed to notify South Korea’s KISA as required, risking fines, while customer data exposure prompts ongoing investigation and notifications.

Image
Image
Image
Image

Overview

  • Dior discovered a data breach on May 7, exposing customer personal information, including names, contact details, and purchase history, but no financial or password data was compromised.
  • The breach affected customers in South Korea and China, with notifications sent to impacted individuals and regulators in both countries.
  • Under Korean law, Dior was required to notify the Korea Internet & Security Agency (KISA) but only informed the Personal Information Protection Commission (PIPC), triggering potential fines of up to 30 million won.
  • Dior is collaborating with cybersecurity experts to investigate and mitigate the breach while advising customers to remain vigilant against phishing scams.
  • The incident highlights challenges global brands face in adhering to diverse data protection regulations and maintaining customer trust after cyberattacks.