Data Security

Major luxury clothing retailers allegedly breached, samples leaked

Glowing red padlocks symbolizing cybersecurity and digital data protection.

Cybernews reports that leading global luxury apparel retail firms Lacoste, Ralph Lauren, Canada Goose, and Carter's were claimed to have had their "supply chain data" stolen by a threat actor, who exposed limited samples for each impacted brand.

Analysis of the samples showed employees' full names and work email addresses, customers' home and email addresses, and internal metadata in numerical values, which may not be as useful for threat actors due to inadequate context, according to Cybernews researchers, who noted the information to have potentially been obtained following a supply chain intrusion.

"The data itself looks like it came from SQL server DBMS, because photo samples included specific SQL server-related metadata, such as row version numbers," said researchers, who added that the threat actor may have exploited breached employee accounts or system misconfigurations to enable the compromise.

Such a development comes months after Canada Goose denied breach of its systems following ShinyHunters' claims of having pilfered over 600,000 records from the luxury performance outerwear and clothing manufacturer. Most of the information allegedly exfiltrated by ShinyHunters was noted by Cybernews analysts to have been dated from 2021 to 2023.

You can skip this ad in 5 seconds