Recommended Free Tools
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Christian Dior Couture says an unauthorized party accessed a customer-information database on January 26, 2025. Dior discovered the potential cybersecurity incident on May 7, 2025, and said it contained the incident, investigated with outside experts, notified law enforcement, and found no evidence of further unauthorized access after January 26.
The exposed information may have included names, addresses, contact details, dates of birth, passport or government-identification numbers and, in a small number of cases, Social Security numbers. Dior said the accessed database did not contain bank-account or payment-card information.
What happened in the Dior cyberattack?
According to Dior’s breach notice, unauthorized access occurred on January 26, 2025. Dior says it identified a potential cybersecurity incident on May 7 and then worked with third-party cybersecurity specialists to investigate it.
Dior said it took steps to contain the incident, notified law enforcement and enhanced network security. The sample U.S. customer letter was dated July 18, 2025. SecurityWeek reported on July 22, 2025, that Dior had posted notices in South Korea and China and that customers in the United States and other countries appeared to have been affected.
#1 Best Overall
The California Attorney General’s filing identifies the organization as Christian Dior Couture SAS and lists January 26, 2025, as the known breach date.
What information may have been exposed?
Dior said the affected database potentially contained:
- First and last names
- Addresses and other contact information
- Dates of birth
- Passport numbers
- Government-identification numbers
- Social Security numbers in a small number of cases
- Other information an individual may have provided to Dior
The exact information varied by person. Dior’s notice does not mean that every affected customer had a passport number or Social Security number in the database, or that every listed category was exposed for every person.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Was payment information stolen?
Dior said the accessed database did not contain bank-account information, credit-card information or other payment information.
That statement applies to the database Dior identified as accessed. It does not establish that every Dior-related system, account or external service has never experienced a separate compromise. A fraudulent card transaction should not automatically be attributed to this incident; contact the card issuer immediately and investigate other possible causes.
How many Dior customers were affected?
The number of affected people was not disclosed in the sources reviewed. Do not infer a victim count from Dior’s global customer base, the number of notices issued or the size of LVMH.
The available materials also do not establish how the attacker gained access, identify a hacking group or explain whether the information was published or sold. Dior described unauthorized access to a Dior database, but did not publicly attribute it to ransomware, a particular vulnerability, malware, insider activity or a third-party vendor.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Is the Dior incident over?
Dior says outside cybersecurity experts verified that the incident was contained and found no evidence that the unauthorized party accessed Dior systems except on January 26, 2025.
Containment does not remove the risk from information that may already have been copied. Names, addresses, birth dates and government-identification details can support phishing, impersonation, account-opening attempts and other identity fraud long after a network intrusion has ended.
What Dior offered affected customers
The sample U.S. notice offered eligible individuals 24 months of Experian IdentityWorks at no cost. It described benefits including:
- Credit monitoring across Experian, Equifax and TransUnion files
- An Experian credit report at enrollment
- Identity-restoration and fraud-resolution assistance
- Identity-theft insurance of up to $1 million, subject to policy terms, exclusions and jurisdictional availability
Identity-theft insurance is not an automatic cash payment for every loss. Coverage depends on the actual policy and applicable jurisdiction.
The sample letter listed October 31, 2025, as the activation deadline. That date has passed, and it may not apply to every recipient or country. If you received a Dior notice, use its engagement number and contact details to ask whether your offer remains available or whether an alternative enrollment path exists. Do not assume that anyone who was not named in an eligible notice qualifies.
Best Value
What affected customers should do now
- Verify the notice. Use Dior’s official data-security page or the contact information printed in your letter. Avoid links in unexpected emails, texts or social-media posts.
- Check whether monitoring is still available. If your letter provides an activation code, confirm its status directly with Dior or Experian. Never pay to activate a service described as free in the notice.
- Review your credit reports. U.S. consumers can use AnnualCreditReport.com, the official source for free credit reports. Look for unfamiliar accounts, inquiries, address changes and incorrect personal information.
- Consider a fraud alert. A fraud alert asks potential creditors to take additional steps to verify your identity before extending credit.
- Consider a credit freeze. A freeze is particularly worth considering if your notice says government-ID or Social Security information was involved. U.S. consumers generally must place freezes separately with Equifax, Experian and TransUnion. Freezes are free, but you may need to temporarily lift one when applying for credit.
- Watch for identity-document fraud. Credit monitoring may not detect every misuse of a passport or government ID. Be alert for suspicious verification requests, government correspondence and impersonation attempts.
- Report suspected fraud quickly. Contact the relevant financial institution, credit bureau, law-enforcement agency and the Federal Trade Commission as appropriate.
How to recognize follow-up scams
Information from a breach can make a fake message appear credible. Treat any message claiming to complete Dior remediation as suspicious if it asks for:
- A payment card to activate “free” monitoring
- Your password or a one-time authentication code
- A full Social Security number by email
- A scan of a passport or driver’s license
- Remote access to your phone or computer
Navigate independently to an official website or call a number from your original notice. Do not provide credentials, authentication codes, payment details or identity documents to an unsolicited contact.
If you did not receive a Dior notice
Not receiving a letter does not prove that you were unaffected. Dior did not publish an affected-person total in the reviewed materials, and reporting indicated that notices involved customers in multiple countries. Contact Dior through an official channel if you believe you may be included, and continue monitoring accounts and credit files for suspicious activity.
U.S.-specific advice about credit bureaus, freezes and the Experian offer may not apply outside the United States. Customers elsewhere should follow local credit-reporting, identity-document and data-protection procedures.
Quick Recap
Sources
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

