Audio By Carbonatix
Cyber criminals have stolen the private details of potentially millions of Balenciaga, Gucci and Alexander McQueen customers in an attack.
The stolen data includes names, email addresses, phone numbers, addresses and the total amount spent in the luxury stores around the world.
Kering, the parent company of the luxury brands, has confirmed the breach and says it disclosed the incident to the relevant data protection authorities.
It said no financial information, such as card details, were stolen.
The firm also says it has emailed customers affected but has not said how many, or made any public statements about the hack.
Legally, the company is not obligated to make any public statements about the breach as long as it has notified all individuals affected through other means.
The cyber criminal behind the attack calls themselves Shiny Hunters.
They claim to have data linked to 7.4m unique email addresses which suggests the total number of individual victims could be similar.
A small sample shared with the BBC as proof contained thousands of customer details which appear to be genuine. Once analysed the files were deleted.
One of the details in the stolen data is "Total Sales" which shows how much money a person has spent with each brand.
Some customers are shown to have spent more than $10,000 with a handful spending $30,000-$86,000 in stores in the small sample analysed by the BBC.
This information is particularly concerning for victims as it could lead to high spenders being targeted by secondary hacks and scams if the hacker decides to leak the information to other criminals.
Shiny Hunters appears to be acting alone and told the BBC over Telegram chat that they breached the luxury brands in April through Kering.
The hacker contacted the French company in early June and claims to have been in on-off negotiations with them over a ransom to be paid in Bitcoin. This is denied by the company which says it has not engaged in any conversations with the criminal.
The company says it has refused to pay the hacker in accordance with long-standing law enforcement advice.
"In June, we identified that an unauthorized third party gained temporary access to our systems and accessed limited customer data from some of our Houses. No financial information - such as bank account numbers, credit card information, or government-issued identification numbers - was involved in the incident," a Kering spokesperson said adding it has since secured its IT systems.
The data breach which happened in April came at the time of a wave of attacks on luxury brands including Cartier and Louis Vuitton also disclosed breaches to customers and the public.
It's not known if those attacks are linked to Shiny Hunters.
In June, cyber security experts at Google issued a warning about a trend of attacks linked to Shiny Hunters that the tech giant also subsequently fell victim to.
The hacker or hackers are known by Google as UNC6040 which have been stealing data through tricking employees into handing over their log in details for internal company Salesforce software.
What to do you if your information has been stolen
Stolen information in cyber-attacks may include your name, address, date of birth and online order history.
Scammers may use these to try and look genuine and contact you pretending to be another organisation, including a bank or government.
So it's important to stay vigilant if you receive suspicious emails, messages or phone calls.
Be aware that scammers often try and press you to do something urgently.
If you do get a call from your bank and are unsure if it's genuine, hang up and call the number on your card or the bank's website.
The National Cyber Security Agency says you should change your password, and use two-factor authentication if possible.
Passwords made up of three random words are harder to crack, and do not reuse password across multiple accounts.
Latest Stories
-
NPP must put aside personal differences to regain power – Paul Afoko
10 minutes -
Government’s fiscal consolidation has suppressed development – Gideon Boako
10 minutes -
Gideon Boako questions government’s economic resilience claims after IMF exit
11 minutes -
Forget the pain and hurt, support me and let’s unite the party – Paul Afoko to NPP
12 minutes -
The right to appeal, the duty to obey court orders, and the legal questions surrounding absconding after conviction
13 minutes -
African Agribusiness Consortium, Jospong announce next batch of 120 Ghanaian scholars for Russia programme
16 minutes -
AAC celebrates return of 118 scholars, reaffirms commitment to transforming Ghana’s agriculture
23 minutes -
PHDC and Touchstone Capital Partners reaffirm commitment to advance US$12 billion Lot 1 agreement
24 minutes -
VADUG urges gov’t to suspend planned vehicle conformity verification programme
31 minutes -
Our democracy is in danger if the NPP is weakened any further – Paul Afoko
46 minutes -
INTERPOL identifies ransomware, AI-powered scams among Africa’s biggest cyber threats
51 minutes -
NPP’s future depends on experience, unity and moving beyond past grievances — Paul Afoko
57 minutes -
Paul Afoko calls for unity in NPP, cites experience and 2016 victory record
1 hour -
Ghanaians lose $1.3m to Mobile Money fraud in first quarter of 2025 – INTERPOL report
1 hour -
IMF exit has exposed Ghana’s economic challenges again – Gideon Boako
1 hour