LVMH A.I CyberSecurity Scoring
LVMH
Company Information
Website:http://www.lvmh.com
Employees number:147,344
Number of followers:2,726,078
NAICS:4483
Industry Type:Retail Luxury Goods and Jewelry
Homepage:lvmh.com
LVMH Risk Score (AI oriented)
Between 700 and 749
LVMHRetail Luxury Goods and Jewelry
Updated:
02/10/2026
02/10/2026
707/1000
Moderate
Ba
LVMH Global Score (TPRM)
xxxx
LVMHRetail Luxury Goods and Jewelry
Score locked

LVMHModerate
Current Score
707Ba (MODERATE)
01000
3 incidents
-79 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
707
SEPTEMBER 2026
711
AUGUST 2026
713
JULY 2026
744
JUNE 2026
745
MAY 2026
740
APRIL 2026
740
MARCH 2026
738
FEBRUARY 2026
815
Breach
11 Feb 2026 • LVMH
Tiffany Korea, Louis Vuitton Korea and Christian Dior Couture Korea: Korean units of Louis Vuitton, Dior, Tiffany fined $24.9 mil. over customer data leaks
South Korea Fines Luxury Brands for Major Data Breaches
736
CRITICAL-79
TIFLVMCHR1770865579
South Korea Fines Luxury Brands $24.9M for Major Data Breaches
South Korea’s Personal Information Protection Commission (PIPC) has imposed a combined 36 billion won ($24.9 million) in fines on the Korean subsidiaries of Louis Vuitton, Dior, and Tiffany for failing to protect customer data from cyberattacks.
Louis Vuitton Korea received the largest penalty 21.4 billion won after hackers breached its systems on three occasions, exposing the personal data of 3.6 million customers, including names, phone numbers, and birth dates. The PIPC cited poor security practices for remote logins, which allowed an external actor to compromise an employee device.
Christian Dior Couture Korea was fined 12.2 billion won following a breach affecting 1.95 million users, where employees were tricked into granting system access to malicious actors. The company remained unaware of the incident for three months. Meanwhile, Tiffany Korea faced a 2.4 billion won fine after a breach exposed the data of 4,600 customers, including names and email addresses.
In a separate case, the PIPC penalized BKR (Burger King Korea) 924 million won for illegally collecting personal data from minors under 13 without guardian consent. MGC Global (Mega MGC Coffee) was fined 642 million won for sending unsolicited marketing messages to customers who had not opted in. Additionally, eight other food and beverage companies were fined for violating data protection laws.
The penalties highlight growing regulatory scrutiny over corporate data security and compliance with South Korea’s privacy laws.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
814
DECEMBER 2025
814
NOVEMBER 2025
813
AUGUST 2025
811
Breach
01 Aug 2025 • LVMH
Gainsight
Gainsight Unauthorized Salesforce Data Access via Stolen OAuth Tokens
770
CRITICAL-41
GAI0292402112125
The incident at Gainsight stemmed from a downstream effect of the August 2025 Salesloft breach, where the Scattered Lapsus$ Hunters group stole OAuth tokens tied to Salesloft’s Drift AI chat integration with Salesforce. These tokens granted unauthorized API access to 760 Salesforce instances, leading to the exfiltration of 1.5 billion records, including passwords, AWS keys, and Snowflake tokens.A subgroup, ShinyHunters, exploited the stolen credentials to breach Gainsight’s systems, extracting customer contact data (names, business emails, phone numbers, regional details), licensing information, and support case contents. Salesforce responded by revoking all active Gainsight-associated tokens and temporarily removing its apps from the AppExchange to mitigate further exposure. While Salesforce clarified that its platform itself was not vulnerable, the breach originated from Gainsight’s external app connections, compromising sensitive corporate and customer data across hundreds of organizations.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JULY 2025
845
Breach
11 Jul 2025 • LVMH
Louis Vuitton
Louis Vuitton UK Customer Data Breach
811
CRITICAL-34
LVM852071225
Louis Vuitton has suffered a data breach where an unauthorised third party accessed its UK operation's systems and obtained customer information such as names, contact details, and purchase history. Although no financial data was compromised, the company warned customers about potential phishing, fraud, or unauthorised use of their information. This is the third breach of LVMH’s systems in the past three months, with previous incidents affecting Louis Vuitton's Korean operation and Christian Dior Couture.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for LVMH ??
What was LVMH's A.I Rankiteo Cyber Score in September 2026 ??
What was LVMH's A.I Rankiteo Cyber Score in August 2026 ??
What was LVMH's A.I Rankiteo Cyber Score in July 2026 ??
What was LVMH's A.I Rankiteo Cyber Score in June 2026 ??
What was LVMH's A.I Rankiteo Cyber Score in May 2026 ??
What was LVMH's A.I Rankiteo Cyber Score in April 2026 ??
What was LVMH's A.I Rankiteo Cyber Score in March 2026 ??
What was LVMH's A.I Rankiteo Cyber Score in February 2026 ??
What was LVMH's A.I Rankiteo Cyber Score in January 2026 ??
What was LVMH's A.I Rankiteo Cyber Score in December 2025 ??
What was LVMH's A.I Rankiteo Cyber Score in November 2025 ??
What is the average per-incident point impact on LVMH's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with LVMH ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view LVMH's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?