DisclosureLens
Social EngineeringRetail & ConsumerRetailPhishingTargetedCustomer Data InvolvedIdentity (basic)Government IDHighContained

Christian Dior Couture

bd_06928ec5a1bbc596 · schema v1 · pii pii-v1

Severity

High

Discovered

May 7, 2025

Filed

Jul 18, 2025

To disclose

10 weeks

Affected

10,878state residents only

Linked

8 filings

Confidence

70%
Full breach record for Christian Dior Couture

Christian Dior Couture SAS reported a cybersecurity incident to the Washington AG. Unauthorized access occurred on Jan 26, 2025, via phishing, affecting client data including names, DOB, government IDs, and SSNs. Discovered May 7, 2025. 10,878 WA residents notified. Incident contained; no evidence of further access.

Washington clock WA AG >30d10 weeks discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 101 days
discovery → filing · 10 weeks / 72 days

Jan 26, 2025

Begins

May 7, 2025

Discovered

Jul 18, 2025

Filed

vs. sector median

+3 wks slower

This filing is one of 8 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (7) · sorted by filing gap

Show 3 more filingsup to 4d gap

Filing propagation · 8 filings · 8 states

View merged incident ↗
Indiana State AGJul 18 · first
California State AGJul 18 · first
Massachusetts State AGJul 18 · first
Vermont State AGJul 18 · first
Oregon State AGJul 18 · first
Washington State AGJul 18 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.