South Korea’s Personal Information Protection Commission fined luxury brands Dior, Louis Vuitton, and Tiffany & Co. a total of $25 million.

The penalties follow a security breach of the companies' Salesforce systems that exposed millions of customer records.

The Scattered LAPSUS$ Hunters hacking group orchestrated the attack as part of an extortion campaign.

Investigators determined the group gained access to corporate Salesforce accounts through social engineering rather than direct software vulnerabilities.

Regulators did not fine Salesforce, but the incident raises security concerns regarding customer data stored on the widely used CRM platform.