ConfirmedData breach

Mytheresa: a data breach

In April 2026, the luxury fashion e-commerce platform Mytheresa was listed as a victim of the ShinyHunters "pay or leak" extortion group . After the ransom deadline passed, the group publicly released the data which contained 84k unique email addresses. The exposed data also included names, phone numbers, physical addresses, purchases and partial credit card data including card type, last 4 digits and expiry date.

The record

Organisation
Mytheresa
Identity
Mytheresaidentified by its domain in a verified breach record
Records affected
84,108 records
Data exposed
Email addresses, Names, Partial credit card data, Phone numbers, Physical addresses, Purchases, Salutations
Sector
Not recorded
Occurred
2026-04-12
Disclosed
2026-05-27
First recorded here
2026-09-09

Sources (1)

One source so far.

  1. Have I Been PwnedFirst reported

    2026-05-27