Skip to main content
Breach Signal

Breach report

Retail

Kering (Gucci, Balenciaga, Alexander McQueen)

Kering, owner of Gucci, Balenciaga, and other luxury brands, confirms hack

French luxury group Kering confirmed that hackers stole personal data on customers of Gucci, Balenciaga, Alexander McQueen and other houses, including how much each shopper had spent, with the ShinyHunters gang claiming about 7.4 million unique records.

Reported by TechCrunch

Records exposed

7.4M

About 7.4 million unique email addresses (hacker claim)

Scale vs. largest on file

When
2025
How they got in
Social engineering to access Salesforce customer database (ShinyHunters)
Sector
Retail

In September 2025, Kering, the Paris-based owner of Gucci, Balenciaga, Alexander McQueen, Saint Laurent and other luxury fashion houses, confirmed that hackers had stolen customer data. The company said it detected the intrusion in June 2025 and that an unauthorized party had gained temporary access to its systems in April, obtaining limited data on some customers of several of its brands. Kering said it had notified the relevant data protection authorities and contacted affected customers.

The stolen information included names, email addresses, phone numbers, home addresses and, notably, the total amount each customer had spent at the brands' stores worldwide. Kering said no financial details such as bank account or credit card numbers and no government identification numbers were taken. The hacking group ShinyHunters claimed responsibility and told reporters it had obtained data tied to about 7.4 million unique email addresses, and that some records showed customers spending tens of thousands of dollars or more.

The breach was part of a much broader 2025 campaign in which ShinyHunters and allied hackers used voice phishing and malicious connected apps to gain access to companies' Salesforce environments, then exported customer records in bulk and demanded payment. Victims included Louis Vuitton, Dior, Tiffany, Chanel, Pandora, Qantas, Allianz Life and Google. The group reportedly contacted Balenciaga in June demanding a ransom, and after talks stalled, shared samples and chat logs with the news site DataBreaches.net.

Kering did not disclose the number of affected customers or whether it paid any ransom. As a European company, Kering was subject to GDPR, which requires regulators to be notified within 72 hours of a company becoming aware of a breach, though the public learned of the incident only months after it was detected. No fine had been announced, and the extortion group went on to claim data from dozens of other Salesforce customers on a leak site later in the year.

The Kering breach illustrates a particular risk for luxury brands: records that combine contact details with spending levels effectively produce a list of wealthy individuals that can be used for targeted scams, fraud or even physical threats. It also showed that cloud platforms are only as secure as the people and integrations that can access them. For companies, the takeaways included training staff to resist phone-based impersonation and restricting third-party app permissions; for customers, heightened caution with unexpected contact.

More from the wire

More in Retail.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.