Latest / Tech Talks With Kinsoft / Luxury Brands Under Siege: Data Breaches Widespread
Transcript
- 0:00Welcome to Tech Talks with Kinsoft. We're the
- 0:01place where we try to make sense of complex tech
- 0:04topics and pull out the insights that really
- 0:06matter for you. Today, we're jumping into something
- 0:08that's been all over the news, probably got you
- 0:10thinking about your own online safety too. We're
- 0:13talking about this recent wave of pretty serious
- 0:15data breaches hitting some big names, major luxury
- 0:19brands, global companies. You've probably seen
- 0:21the headlines, but we want to get beyond that,
- 0:24look at the deeper story. How do these attacks
- 0:26actually happen? Why is your data maybe sitting
- 0:29with these companies, such a target? And what
- 0:31does it all really mean? That's exactly right.
- 0:33We've been digging through quite a few reports,
- 0:35analyses, looking at this trend. And it is concerning.
- 0:39You see these really sophisticated cyber attacks
- 0:41hitting well -known companies like Chanel, Louis
- 0:43Vuitton, even Qantas. So our goal today is...
- 0:48to pull out the patterns we're seeing, expose
- 0:50the methods these attackers are using because
- 0:52they are evolving, and maybe most importantly,
- 0:55give you some practical knowledge, things you
- 0:57can actually use to protect yourself better online,
- 0:59because it really isn't just about these big
- 1:01corporations. It's about your personal information.
- 1:04Okay, let's start there then. Let's look at Chanel.
- 1:06They recently confirmed a breach, right, affecting
- 1:08U .S. clients. Yes, discovered July 25th. Unauthorized
- 1:12access, but interestingly, it was to a database
- 1:15hosted by a third -party provider. Not Chanel's
- 1:18main systems directly, it seems. And what kind
- 1:20of data was involved? Names, email addresses,
- 1:22mailing addresses, phone numbers, stuff people
- 1:24gave when they contacted the U .S. Client Care
- 1:26Center. The good news, relatively speaking, is
- 1:29that they stated no financial details were compromised
- 1:32in this specific instance. Okay, but still, names,
- 1:36addresses, phone numbers, that's quite a bit.
- 1:38Why luxury brands, though? Why are they such
- 1:41attractive targets? Is it just about getting
- 1:43lists of wealthy people? Well, that's part of
- 1:46it, sure. High net worth individuals are seen
- 1:48as valuable targets themselves. But it's more
- 1:52than just that. Attackers can use this kind of
- 1:54detailed personal data, maybe combine it with
- 1:57purchase history if they get that, to craft really
- 1:59convincing scams, targeted phishing, social engineering.
- 2:02Ah, so the data itself allows for more sophisticated
- 2:05follow -on attacks. Exactly. Plus, think about
- 2:08the brand reputation. Luxury brands thrive on
- 2:11trust, exclusivity. Damage that, and you create
- 2:14leverage for extortion. And a really critical
- 2:17thread here, something we're seeing again and
- 2:19again, including with Chanel, is this link to
- 2:21third -party service providers. Specifically,
- 2:23Salesforce instances seem to be involved quite
- 2:26often, as Bleeping Computer reported. Right,
- 2:28Salesforce. So it's not necessarily Salesforce
- 2:30itself being hacked. but how companies use Salesforce.
- 2:34Precisely. That's the key distinction. It's a
- 2:36supply chain vulnerability. Salesforce has been
- 2:39pretty clear in their statements. They say their
- 2:40core platform is secure. They're pointing towards
- 2:43issues not being down to a known flaw in their
- 2:45system, but more about how customers manage their
- 2:48security settings. So customer responsibility.
- 2:51Yes. They're highlighting the rise in sophisticated
- 2:54phishing and social engineering. targeting their
- 2:57clients' employees. And Salesforce is urging
- 2:59customers, you know, follow best practices. Use
- 3:03multi -factor authentication, that's MFA or 2FA,
- 3:06that extra code or confirmation. Enforce least
- 3:09privilege access, meaning people only get access
- 3:11to exactly what they need for their job, nothing
- 3:14more. And crucially, monitor those connected
- 3:16apps very closely. It makes sense for Salesforce
- 3:19to emphasize customer responsibility. But you
- 3:22wonder, these platforms are powerful but complex.
- 3:24Could that complexity itself create openings
- 3:27even for companies trying to do the right thing?
- 3:29That's a really sharp point. Power and flexibility
- 3:31often come hand in hand with complexity. Misconfigurations,
- 3:35maybe just not keeping up strictly with best
- 3:38practices. Yeah, that can definitely create gaps
- 3:40attackers can exploit. And this ties into who's
- 3:43actually doing this. The Chanel breach, for instance,
- 3:45seems to be part of a larger case. campaign.
- 3:47It's been attributed to the shiny hunters group.
- 3:51Shiny hunters. They've been around for a while,
- 3:52known for data theft, extortion. That's them.
- 3:55But what's really interesting and maybe a bit
- 3:57confusing is that there were reports back in
- 4:00late June 2025 of arrests linked to shiny hunters
- 4:04and their forum, breach forums. Arrests. But
- 4:08the attacks are still happening. Apparently so,
- 4:10which raises big questions, doesn't it? How are
- 4:12they pulling this off despite law enforcement
- 4:14action? Yeah, what does that tell us? Well, it
- 4:16might suggest these groups are more decentralized
- 4:18than we think. Maybe arresting one or two key
- 4:20figures doesn't stop the whole operation. Or
- 4:23perhaps others just pick up the mantle. It highlights
- 4:26this constant cat and mouse game. And Google's
- 4:29threat intelligence group, GTIC, they reported
- 4:31in June on a group called UNC6040, which seems
- 4:34linked to these attacks. They're using some pretty
- 4:37sophisticated social engineering, mostly phishing,
- 4:40that's voice phishing, over the phone and regular
- 4:43email phishing, often pretending to be IT support.
- 4:46So they're actually calling employees or sending
- 4:49emails that look like they're from internal tech
- 4:51support. That's bold. Incredibly bold and effective.
- 4:54They trick employees into going to Salesforce's
- 4:57connected app. Setup page. Then they get the
- 5:00employee to enter a connection code. This code
- 5:02links a malicious OOTH app. Okay, hang on. OOTH
- 5:05app, what does that do exactly? Think of it like
- 5:08giving permission. You know how sometimes you
- 5:10sign into a new website using your Google or
- 5:13Facebook account? That uses OOTH. You're granting
- 5:17that website limited access to some of your Google
- 5:19or Facebook info without giving it your main
- 5:22password. Here, the attackers trick the employee
- 5:25into granting their malicious app permission
- 5:27to access data within the company's Salesforce
- 5:29system. Wow. And they disguise the app. Yeah.
- 5:33Often as something harmless sounding like My
- 5:35Ticket Portal. Once it's connected, the attackers
- 5:37can just siphon off sensitive customer data from
- 5:39the CRM system. So the CRM, the Customer Relationship
- 5:43Management System, that's where all the customer
- 5:45details live. Names, contact info, maybe purchase
- 5:48history. Exactly. It's the crown jewels of customer
- 5:51data. for many companies. And it's not just the
- 5:54OOOTH trick. They're also stealing login credentials
- 5:56and those MFA tokens, the one time codes using
- 5:59fake login pages that look identical to the real
- 6:02thing. That makes it incredibly hard for an ordinary
- 6:04employee to spot. They're exploiting human trust.
- 6:07Absolutely. It's less about breaking down technical
- 6:10walls sometimes and more about just walking through
- 6:12the front door because someone held it open for
- 6:14you, essentially. And this isn't just Chanel.
- 6:16You mentioned this is a wider campaign. Oh, yes.
- 6:19We've seen a whole string of major brands disclosing
- 6:22similar breaches in recent months. LVMH subsidiaries
- 6:25think Louis Vuitton, Dior, Tiffany & Co. Tiffany
- 6:30Korea specifically mentioned a vendor platform
- 6:32being infiltrated. Adidas, Qantas, Allianz Life.
- 6:36All reporting breaches link to these third -party
- 6:38CRM platforms. It really does look like a coordinated
- 6:41effort using a similar playbook. The scale is
- 6:43quite something. Louis Vuitton, for example,
- 6:45that breach had a huge international footprint,
- 6:47didn't it? Massive. Confirmed July 2nd, 2025.
- 6:50It hit customers in Australia, Hong Kong, where
- 6:54they said 419 ,000 customers were impacted. South
- 6:57Korea, Turkey, the UK, Italy, Sweden, Spain,
- 7:00New Zealand. Pretty much global. And what data
- 7:03was exposed there? Similar to Chanel? Similar,
- 7:05but maybe even broader in some ways. Full names,
- 7:09gender, country, postal addresses, emails, phone
- 7:12numbers, date of birth, purchase history. Again,
- 7:15they stated no passwords or financial details
- 7:17directly. But worryingly, in some cases, passport
- 7:21numbers were also exposed. Passport numbers.
- 7:24Okay, that really elevates the risk. Identity
- 7:27theft becomes a much bigger concern. Absolutely.
- 7:30And you saw the customer reaction, right, especially
- 7:32in Australia, where some people apparently didn't
- 7:35get notified for up to 20 days after LV detected
- 7:38the breach. 20 days? That seems like a long time.
- 7:41It does. And people were understandably upset.
- 7:43We saw comments online, like on Reddit, folks
- 7:46angry about the sheer amount of data access,
- 7:48name, address, date of birth, and questioning
- 7:51why companies even need to collect all that unnecessary...
- 7:54PII or personally identifiable information in
- 7:57the first place. That's a fair point. Does a
- 7:59luxury brand really need your date of birth to
- 8:01sell you a handbag? It makes you think about
- 8:03data minimization. It really does. And then there's
- 8:05Qantas, not a luxury brand, but a major airline,
- 8:09huge customer base. They also got hit. Right.
- 8:11When was that? Between June 30th and July 2nd,
- 8:142025, again via a third -party system, this time
- 8:18a contact center system based in Manila, affected
- 8:21about 5 .7 million unique customer records. 5
- 8:24.7 million? Wow. Yeah. Mostly names, emails,
- 8:28frequent flyer details. But for around 1 .7 million
- 8:31of those, it also included addresses, dates of
- 8:33birth, phone numbers, gender. Qantas also emphasized
- 8:36no passwords, credit card details, or passport
- 8:39info were taken. So again, that consistent pattern.
- 8:41So when you pull back and look at all these incidents
- 8:43together, Chanel, LV, Qantas, others, what's
- 8:46the big picture here? The big picture is that
- 8:49the threat landscape is constantly shifting.
- 8:51And supply chain security is maybe one of the
- 8:54most critical weak points right now. You just
- 8:57have to look at the list of breaches here in
- 8:58Australia over the last few years, 2018 to 2025.
- 9:01It's relentless. It hits everyone. Homebuilders
- 9:03like Metricon, big super funds like REST and
- 9:05Australian Super, universities, government agencies.
- 9:08It really drives home that your data isn't just
- 9:10risked by the company you give it to directly.
- 9:11It's risked by their vendors, their service providers,
- 9:14that whole interconnected web your data travels.
- 9:16That's a sobering thought. So for these brands
- 9:19like Chanel, Louis Vuitton, where trust and loyalty
- 9:22are everything. How do they even begin to rebuild
- 9:25after something like this? It's not just about
- 9:27fixing the technical hole, is it? Not at all.
- 9:29Communication is absolutely key. Clear, honest,
- 9:32timely information about what happened, who was
- 9:35affected, what data was involved, and what steps
- 9:38customers should take. Any ambiguity or delay
- 9:40just makes things worse. And then internally,
- 9:42they need robust, tested incident response plans.
- 9:45Not just a plan sitting on a shelf, but one they
- 9:47actually practice. And cybersecurity training
- 9:50for everyone has to be part of the culture, not
- 9:52just an IT thing. Even then, the social engineering
- 9:54aspect we talked about makes it incredibly tough.
- 9:56It really does sound like a constant battle.
- 9:59Okay, so let's bring it back to our listeners.
- 10:01What can you do? Faced with all this, how can
- 10:04you better protect your own digital self? Based
- 10:07on what we've discussed today, especially these
- 10:09kinds of attacks, here are a few key actions.
- 10:12First, passwords. We always say it, but it's
- 10:15crucial. Strong, unique passwords for every site.
- 10:19Don't reuse them. Use a mix of letters, numbers,
- 10:21symbols. And honestly, consider using a password
- 10:24manager. It makes managing unique passwords so
- 10:27much easier and more secure. That's a great first
- 10:29step. Second, two -factor authentication, or
- 10:322FA. Enable it everywhere you possibly can. But
- 10:36thinking about how these attackers are trying
- 10:38to grab MFA tokens, maybe prioritize the more
- 10:41secure types of 2FA if they're offered. Right,
- 10:43like authenticator apps on your phone, Google
- 10:46Authenticator, Authy, those kinds. Or even better,
- 10:48hardware security keys, like YubiKey. They're
- 10:51generally seen as stronger than just getting
- 10:53a code via SMS text message, which can sometimes
- 10:55be intercepted or phished. Good point. Okay,
- 10:58third, monitor your accounts. Keep an eye on
- 11:01your bank statements, credit card activity, obviously.
- 11:03But maybe also check things like your frequent
- 11:06flyer balance or loyalty points. Those are targets
- 11:08too now. Set up transaction alerts if you can.
- 11:11Vigilance is key. Fourth, software updates. Keep
- 11:14your phone, your computer, your apps updated.
- 11:17Those updates often patch security holes that
- 11:20attackers are actively looking for. Don't ignore
- 11:22them. Simple but effective. Fifth. Think before
- 11:25you share. Be really mindful about what personal
- 11:27information you hand over online. Do they really
- 11:30need your exact date of birth for that newsletter,
- 11:32your full home address for that contest? Given
- 11:35how this data is being used in breaches, maybe
- 11:37be a bit more reserved if it's not strictly necessary.
- 11:40Data minimization on a personal level. Exactly.
- 11:43And finally, number six. Be super wary of phishing
- 11:47and vishing, those fake emails, texts, even phone
- 11:51calls, especially if they mention some personal
- 11:53detail they might have gotten from a previous
- 11:55breach to sound legitimate, or if they ask you
- 11:57to click a link, download something, or provide
- 11:59login details or codes. If you're unsure, don't
- 12:02click, don't respond. Contact the company directly
- 12:05through their official website or phone number
- 12:07that you look up yourself. Never use the links
- 12:10or numbers in the suspicious message. That skepticism
- 12:12is probably your best defense against those social
- 12:14engineering tricks. Yeah. You know, looking at
- 12:17the scale and the cleverness of these recent
- 12:19attacks, it really hits home. Cyber threats aren't
- 12:22just some technical issue for the IT folks anymore.
- 12:24They're a core business risk, and they're deeply
- 12:27personal for all of us. Maybe the question we
- 12:29need to ask isn't if our data might get exposed
- 12:31in some breach, but when it happens, how ready
- 12:34are we to deal with it? I think that's the right
- 12:36way to frame it. Understanding how these threat
- 12:39actors operate, where the vulnerabilities lie,
- 12:41especially in these third -party systems, it
- 12:44gives you power. It just underscores the constant
- 12:47need for strong security, both for us as individuals
- 12:50and for the businesses we interact with. It's
- 12:52a shared responsibility, really. Absolutely.
- 12:54Well, thank you for joining us on this edition
- 12:56of Tech Talks with Kinsoft. If you're thinking
- 12:58about your own business's security posture or
- 13:00your IT needs in general after hearing all this,
- 13:03you can find out more about how we can help at
- 13:05www .kinsoft .com .au. Stay informed, stay vigilant
- 13:09out there. We'll catch you next time with more
- 13:11insights to help you navigate this complex digital
- 13:14world.