The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
South Korea’s Personal Information Protection Commission (PIPC) fined the Korean subsidiaries of Louis Vuitton, Christian Dior Couture and Tiffany a combined 36.033 billion won—approximately $24.9 million to $25 million—after separate customer-data breaches involving cloud-based customer-management systems.
The regulator also imposed 10.8 million won in additional administrative penalties and ordered all three companies to publish the sanctions on their websites. The decision was adopted on February 11, 2026, and announced on February 12.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Network Security, Firewalls, and VPNs | $66.62 | Buy on Amazon |
| 2 |
|
Network Security, Firewalls, and VPNs: . (Issa) | $60.87 | Buy on Amazon |
| 3 |
|
TP-Link ER605, Wired Gigabit VPN Router | $49.99 | Buy on Amazon |
| 4 |
|
Cybersecurity for Small Networks: A Guide for the Reasonably Paranoid | $32.51 | Buy on Amazon |
What South Korea fined the companies for
This was not one identical breach affecting a single corporate entity. The PIPC sanctioned three South Korean operating companies: Louis Vuitton Korea Ltd., Christian Dior Couture Korea Co. Ltd. and Tiffany Korea Co. Ltd.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallAll three cases involved SaaS-based customer-management systems. The regulator’s findings focused not only on the employees who were deceived or the malware used by attackers, but also on the companies’ security configuration, access controls, monitoring and incident response.
#1 Best Overall
| Company | Administrative fine | Approximate affected population | Primary finding |
|---|---|---|---|
| Louis Vuitton Korea | 21.385 billion won | About 3.6 million people | Malware on an employee device led to stolen SaaS credentials and unauthorized access. |
| Christian Dior Couture Korea | 12.236 billion won | About 1.95 million people | Voice phishing, weak access and download controls, inadequate log reviews and delayed notification. |
| Tiffany Korea | 2.412 billion won | About 4,600 people | Voice phishing, unauthorized SaaS access, weak IP and bulk-download controls and delayed notification. |
The precise figures come from the PIPC’s enforcement announcement. English-language coverage from Yonhap rounded the individual fines and reported a total of roughly 36 billion won, or $24.9 million.
How the three breaches happened
Louis Vuitton: malware and stolen credentials
The PIPC said employee devices were infected with malware, allowing attackers to obtain account information for the company’s SaaS customer-management service. Customer information was exposed in three incidents between June 9 and June 13, 2025.
Approximately 3.6 million people were affected. Yonhap reported that the exposed information included names, phone numbers and birth dates.
The regulator found that Louis Vuitton Korea had not sufficiently restricted access to the system by IP address and had not applied sufficiently secure authentication for external access. Those weaknesses made a stolen account more useful to an attacker because access was not adequately limited to trusted networks, devices or stronger verification methods.
Dior: voice phishing and delayed detection
Christian Dior Couture Korea’s incident began when a customer-service employee was deceived in a voice-phishing attack. The attacker used the resulting access to enter the SaaS environment and expose information belonging to approximately 1.95 million people.
The PIPC said Dior had not sufficiently restricted access by IP address or limited tools capable of downloading large quantities of data. It also found that Dior failed to review access logs at least monthly. That contributed to the company’s failure to identify the leak for more than three months.
Rank #2
- Available with the Cloud Labs which provide a hands-on, immersive mock IT infrastructure enabling students to test their skills with realistic security scenarios
- New Chapter on detailing network topologies
- The Table of Contents has been fully restructured to offer a more logical sequencing of subject matter
- Introduces the basics of network security—exploring the details of firewall security and how VPNs operate
- Increased coverage on device implantation and configuration
Dior became aware of the incident on May 7, 2025. According to the PIPC’s later enforcement decision, it reported the incident on May 12, beyond the applicable 72-hour period without an accepted justification. The 72-hour finding is a requirement under the relevant South Korean privacy regime; it should not be treated as a universal breach-notification deadline in every country.
Recommended Free Tools
Yonhap reported that the Dior case involved names and email addresses. The public material does not establish that payment-card numbers, passwords, passport details or purchase histories were exposed.
Tiffany: voice phishing and bulk-download exposure
Tiffany Korea’s breach also began with a customer-service employee being tricked by voice phishing. The attacker obtained access to the company’s SaaS customer-management system, exposing information relating to approximately 4,600 people.
The PIPC found that Tiffany had not sufficiently restricted access by IP address and had not adequately limited bulk-download functionality. The regulator’s release says the marketing-oriented SaaS system had been in use since 2021.
Tiffany became aware of the incident on May 9, 2025. The PIPC said the company reported the matter and notified affected people on May 22, beyond the applicable 72-hour period absent a valid justification.
Yonhap reported that names and email addresses were involved in the Dior and Tiffany incidents. The publicly available summaries do not support broader claims about the types of data exposed.
Rank #3
- 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
- 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
- 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
- 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
- Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q
Timeline of the cases
- January 2025: Dior’s incident reportedly occurred around this period, according to an earlier PIPC investigation notice.
- April 2025: Tiffany’s incident reportedly occurred around this period.
- May 7, 2025: Dior detected its incident.
- May 9, 2025: Tiffany detected its incident.
- May 12, 2025: Dior reported and notified the breach, according to the later enforcement decision.
- May 22, 2025: Tiffany reported and notified the breach, according to the later enforcement decision.
- May 30, 2025: The PIPC announced investigations into Dior and Tiffany.
- June 9–13, 2025: Louis Vuitton experienced three customer-data exposure incidents.
- February 11, 2026: The PIPC’s plenary meeting adopted the sanctions.
- February 12, 2026: The commission publicly announced the fines and other measures.
The earlier PIPC investigation notice confirmed that the Dior and Tiffany cases involved employee account information being used to access SaaS customer-management services.
Why cloud software did not remove the companies’ responsibility
The PIPC treated the cloud customer-management platforms as personal-information processing systems under South Korean law. In practical terms, using SaaS did not allow the companies to shift responsibility for their own access and security decisions to the software provider.
The findings highlight a shared-responsibility principle that applies broadly to companies using CRM, marketing, support and customer-service platforms: the provider may operate the infrastructure, but the customer organization still controls important settings, user permissions and workflows.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
The PIPC identified or emphasized several safeguards:
- IP-based restrictions: Limit access to approved networks, locations or devices where appropriate.
- Strong authentication: Use multi-factor authentication and, where available, phishing-resistant methods for external access.
- Least privilege: Give employees only the data and functions required for their roles.
- Bulk-download controls: Separate ordinary customer-service access from the ability to export large data sets.
- Logging and monitoring: Retain access logs and review them on a defined schedule, with alerts for unusual locations, devices or download volumes.
- Account governance: Disable inactive accounts promptly and remove standing privileges that employees no longer need.
- Employee supervision: Combine technical protections with training and testing against phishing and voice phishing.
- Incident response: Document how the company will detect, investigate and report a suspected breach within the applicable legal deadline.
No individual measure is a complete solution. MFA may not stop every attack if an employee is manipulated into approving access. IP restrictions can be difficult for mobile or distributed workforces. Download limits can disrupt legitimate marketing and customer-service operations. Log retention is also ineffective if nobody reviews the logs or investigates alerts.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Were the cases part of one wider hacking campaign?
Specialist security coverage linked the three incidents to a broader campaign targeting SaaS environments and discussed possible connections to groups using names such as ShinyHunters or Scattered LAPSUS$ Hunters. SecurityWeek and MLex also connected the cases in reporting about Salesforce-related attacks.
That attribution should be kept separate from the official enforcement finding. The PIPC’s public announcement describes three incidents involving SaaS customer-management systems but does not establish that one attacker conducted all three cases or definitively identify Salesforce as the platform. It is more accurate to describe the shared campaign theory as specialist reporting, not as a final finding stated by the South Korean regulator.
Free tools Windows power users keep installed
One-click scans. No signup required.
What customers should do
The reported affected populations total approximately 5.55 million people when the three figures are added, but the numbers are approximate and may not represent unique individuals. Customers should rely on the affected company’s own notification for their specific information and recommended steps.
Because names, email addresses and other contact information may be used in follow-up impersonation scams, customers should:
- Be cautious of unexpected calls or emails referring to luxury purchases, loyalty accounts or customer-service issues.
- Never provide passwords, one-time codes or account-recovery information to an unsolicited caller.
- Verify the company’s contact details independently rather than using links or phone numbers in a suspicious message.
- Watch for unusual account activity, targeted phishing and unexpected password-reset requests.
- Contact the brand through an official channel if a message claims that additional action is required.
There is no basis in the cited public summaries to tell every affected customer to reset a password or replace a payment card. Those steps make sense only if the company confirms that the relevant credentials or financial information were exposed, or if the same password was reused elsewhere.
The broader compliance lesson
The enforcement action is significant beyond the luxury sector. It shows that a company can face regulatory consequences when a breach results from weaknesses in how it configures and monitors a cloud platform, even when the initial access came from malware or an employee being deceived.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesFor privacy and security teams, the practical question is not simply whether a SaaS vendor advertises strong infrastructure security. It is whether the customer organization has configured authentication, network restrictions, permissions, exports, logging and incident-response processes to match the sensitivity of the data and the requirements of the jurisdiction in which it operates.
The PIPC’s orders also included website publication of the sanctions. That makes the action more visible than a fine alone and reinforces that data-protection failures can create regulatory, operational and reputational costs for the local entity responsible for customer information.
Bottom line: South Korea’s decision concerned three separate breaches and three Korean subsidiaries—not a single fine against LVMH as a parent company. The combined administrative fines were 36.033 billion won, roughly $25 million, plus 10.8 million won in additional penalties. The central message is that using cloud software does not excuse weak access controls, excessive download privileges, poor monitoring or delayed breach notification.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

