Christian Dior Couture SAS experienced a data breach affecting a database containing personal information of Dior clients. The breach discovered on May 7, 2025, and an investigation determined that a cybercriminal accessed the Dior database on Jan. 26, 2025.
The data breach was also disclosed to the California, Massachusetts, New Hampshire, Texas, Washington, and Vermont Attorneys Generals' offices on July 18 and July 21, 2025, respectively. The incident is considered severe due to the nature of the data exposed, which could be used in identity theft or fraud schemes if obtained by malicious actors.
Information Exposed:
Impact by State:
Christian Dior Couture SAS contained the incident and engaged cybersecurity experts to investigate and secure their systems. The company is also offering 24 months of Experian IdentityWorks credit monitoring services.
If you receive a notice from Christian Dior about this breach, you may want to:
A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.
This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.