Overview
- Dior discovered a data breach on May 7, exposing customer personal information, including names, contact details, and purchase history, but no financial or password data was compromised.
- The breach affected customers in South Korea and China, with notifications sent to impacted individuals and regulators in both countries.
- Under Korean law, Dior was required to notify the Korea Internet & Security Agency (KISA) but only informed the Personal Information Protection Commission (PIPC), triggering potential fines of up to 30 million won.
- Dior is collaborating with cybersecurity experts to investigate and mitigate the breach while advising customers to remain vigilant against phishing scams.
- The incident highlights challenges global brands face in adhering to diverse data protection regulations and maintaining customer trust after cyberattacks.