Last updated 1 month ago
Mytheresa, a luxury fashion e-commerce platform headquartered in Germany, suffered a data breach disclosed in April 2026. The incident exposed 84,108 unique email addresses along with associated personal and financial data. The breach was publicly disclosed after the extortion group ShinyHunters released the stolen data following an unpaid ransom demand.
The attack was carried out by the ShinyHunters extortion group, which employed a 'pay or leak' strategy. After the ransom deadline passed, the group publicly released the exfiltrated dataset. The compromised data includes names, phone numbers, physical addresses, purchase histories, and partial credit card information (card type, last four digits, and expiry date). No specific initial access vector or exploitation technique was disclosed.
No further post-incident developments such as regulatory actions, litigation, or ransom payment details were reported in the available information.
Extortion group ShinyHunters claimed breach and leaked data after ransom deadline passed
Mytheresa's breach underscores the critical need for robust data protection measures in e-commerce, particularly for payment card data. The exposure of partial credit card details suggests insufficient tokenization or encryption of sensitive financial information at rest. Organizations handling high-value customer data should implement strict access controls, regular security audits, and a comprehensive incident response plan to mitigate the impact of extortion-driven attacks.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector
Threat Actor