[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f332icqpycppc9":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"publishedAt":12,"modifiedDate":11,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":21,"affectedCount":21,"affectedCountStatus":22,"affectedCountLowerBound":12,"affectedCountUnit":23,"hasEnglishDescription":4,"contentLocale":24,"availableLocales":25,"translations":27,"severity":30,"dataClasses":31,"description":39,"seoTitle":40,"seoDescription":41,"logoUrl":42,"isVerified":4,"isSensitive":43,"isSpamList":43,"isMalware":43,"company":44},"6a452308a20f867c8ba8e76f","mytheresa","Mytheresa Data Breach","mytheresa.com","2026-04-12T00:00:00.000Z","2026-05-27T05:17:45.000Z",null,"2026-07-19T00:03:28.157Z","Verified third-party breach record and contemporary reporting","https:\u002F\u002Fcybernews.com\u002Fnews\u002Fshinyhunters-myteresa-zara-carnival-7eleven-data-leak\u002F",[15,17,18,19,20],"https:\u002F\u002Fdatabreach.com\u002Fbreach\u002Fmytheresa-2026","https:\u002F\u002Flunarcyber.com\u002Fbreach-catalog\u002Fmytheresa-com\u002F","https:\u002F\u002Fwww.dexpose.io\u002Fshinyhunters-targets-german-retailer-mytheresa\u002F","https:\u002F\u002Fwww.mytheresa.com\u002F",84108,"known","unknown","en",[24,26],"tr",{"en":28,"tr":29},{"slug":7},{"slug":7},"Medium",[32,33,34,35,36,37,38],"Email addresses","Names","Partial credit card data","Phone numbers","Physical addresses","Purchases","Salutations","\u003Cp>The Mytheresa data breach is a verified security incident dated April 12, 2026, related to customer data of the Germany-based luxury fashion e-commerce brand. The record affects 84,108 unique email addresses and includes customer name, phone number, physical address, purchase information, salutation, and partial payment card data. Partial card data is limited to fields such as card type, last four digits, and expiration date. Full card number or password fields are not included in the verified data classes. Nevertheless, the combination of email, address, phone, and shopping history increases the risk of fraud themed around fake delivery, fake returns, payment verification, and customer support.\u003C\u002Fp>\u003Cp>This record considers the unique email count as the main user impact. Some breach indexes show numbers close to 84,370 rows but different; this difference may stem from distinguishing unique emails from raw rows or duplicate customer records. The LeakData record maintains the verified main counter of 84,108 unique email values. The event date should be kept as April 12, 2026, and the database insertion date as May 27, 2026. The last internal system maintenance or bulk update time should not be shown as the date of this event.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data verified in Mytheresa records are email addresses, names, phone numbers, physical addresses, purchase information, salutations, and partial payment card data. Since passwords are not included, this incident should not be presented as a direct password compromise. The main source of risk is the combined visibility of customer identity and shopping context. Name, phone number, address, and purchase history make it easier for an attacker to generate fake messages resembling legitimate customer service communications.\u003C\u002Fp>\u003Cp>Partial card data alone may not be sufficient to make a payment; however, pieces such as the card type, last four digits, and expiration date can be used to build trust in social engineering. The attacker may contact the customer under the pretext of an old order, return, delivery delay, customs fee, or card renewal. In the context of luxury fashion shopping, this can also lay the groundwork for more targeted fraud attempts with themes such as high-value orders, VIP customers, gift delivery, or membership benefits.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The verified scope of this record is 84,108 unique email addresses. In nearby sources, 84,370 rows of information are also seen; however, this number has not been added to the main affected user count. The number of rows can increase due to multiple purchase records for a single customer, repeated address information, or the merging of different table segments. Therefore, the main value shown to the user is maintained as the number of unique emails.\u003C\u002Fp>\u003Cp>Data classes are limited to a verified list: email addresses, names, partial card data, phone numbers, physical addresses, purchase information, and salutations. Passwords, full card numbers, bank accounts, ID documents, passports, private messages, or account session keys should not be added to this record. The incident is a customer data leak; unverified claims about the system access method, how long the attacker remained within internal systems, or whether all internal data fields were affected should not be shown to the user.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The first group at risk are customers who have a Mytheresa account or use the same email address while shopping from the brand. When these individuals match with name, phone, address, and purchase history, they become more susceptible to fake order tracking, fake return approval, or fake payment verification messages. The context of luxury product shopping can help the attacker make the message more personal and convincing.\u003C\u002Fp>\u003Cp>The second group consists of people who use the same phone number for bank, e-wallet, delivery, cargo, and other shopping services. The appearance of the phone number and address together can strengthen the pretext of a fake cargo call or delivery verification. The third group consists of employees who open personal shopping accounts with their corporate email addresses. Such a match does not mean access to the company system; however, an attacker can send more targeted messages by using the employee's name and shopping context.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users appearing in the Mytheresa registration should carefully check messages related to returns, delivery, payment, customs, subscription, or customer support, especially those received via email and phone. Instead of logging in through the link in the message, the known address of the service should be preferred. Even if the last four digits of the card or the order context are mentioned in the message, this alone does not indicate that the message is trustworthy. Full card numbers, security codes, one-time codes, or account passwords should not be shared in phone calls.\u003C\u002Fp>\u003Cp>The user should check the last sessions, registered addresses, saved cards, and order history in shopping and payment accounts. If a suspicious transaction or an unrecognized delivery address is noticed, support should be obtained from the card provider and the relevant service. Even if the password field is not in verified data classes, if the same email address exists in other services, multi-factor authentication should be kept enabled. The email account should also be strongly protected, as it is the recovery center for all shopping accounts.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>This incident shows that not only the password but also the customer profile and shopping history create a lasting risk in e-commerce accounts. Users should delete unnecessary saved cards, remove old delivery addresses, and use separate, strong passwords for shopping accounts. Email addresses should be separated according to services if possible; notifications and card transaction alerts should be kept on for high-value purchases.\u003C\u002Fp>\u003Cp>From the perspective of institutions, this record reminds the importance of data minimization, access control, and customer support verification processes in retail systems. Name, phone, address, and partial card fields can be useful for marketing or order management; however, when retained longer than necessary, they increase the risk of fraud. E-commerce companies should segment customer data, reduce old records, provide social engineering alerts to support teams, and regularly monitor suspicious data access.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>A user who sees a Mytheresa result on LeakData should evaluate this record as a customer profile and payment fraud risk. The result includes 84,108 unique email addresses along with name, phone, physical address, purchase information, salutation, and partial card fields. Since password or full card number data are not included in verified data classes, the alert level should be understood within this limit; however, the caution level should be kept high regarding customer support and delivery-related fraud.\u003C\u002Fp>\u003Cp>The practical order is clear: first secure the email account, then check the cards, delivery addresses, and recent orders registered on Mytheresa and other shopping accounts. If there is any suspicious card activity, the card provider should be contacted. The user should also be cautious of fake return and delivery messages on other shopping services where they are registered with the same email and phone number. If an account was opened with a corporate email, the result should be shared with the security team.\u003C\u002Fp>","Mytheresa Data Breach (84.1 Thousand Reported Records)","Mytheresa Data Breach. 84.1 Thousand reported records are reported. Reported data: Email addresses, Names, Partial credit card data. Review the scope, risks…","\u002Fuploads\u002Flogo\u002Fmytheresa_com.webp",false,{"name":45,"sector":46,"country":47,"website":9,"websiteArchiveUrl":48,"websiteStatus":48,"websiteCheckedAt":12},"Mytheresa","Luxury Fashion E-commerce","Germany",""]