Skip to main content
Back to overview
High

Mytheresa experiences data breach affecting over 84,000 records

The Mytheresa data breach exposed 84,108 records including Email addresses, Names, Partial credit card data, Phone numbers, Physical addresses, Purchases, Salutations.

Key points

  • The Mytheresa data breach exposed 84,108 records including Email addresses, Names, Partial credit card data, Phone numbers, Physical addresses, Purchases, Salutations. This breach has been verified by HaveIBeenPwned. Affected users should check HaveI
  • Mytheresa experiences data breach affecting over 84,000 records

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Phishing Social Engineering

Threat source not confirmed

03

Potential impact

Data Exposure

Confidentiality

Published
Apr 12, 2026
Updated
Aug 6, 2026
Confidence
High
Evidence
2 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch phishing, executive impersonation and account-takeover exposure.

Business impact

Potential fraud or account takeover risk
Impact area
Confidentiality
Likely asset
User or customer data

Mentioned entities

MytheresaData DisclosureMytheresaThe MytheresaEmailNamesPartialPhonePhysicalPurchases

Quick context

Questions about this signal

What happened in this signal?

The Mytheresa data breach exposed 84,108 records including Email addresses, Names, Partial credit card data, Phone numbers, Physical addresses, Purchases, Salutations. This breach has been verified by HaveIBeenPwned. Affected users should check HaveIBeenPwned.com and take immediate steps to protect their accounts. In April 2026, the luxury fashion e-commerce platform Mytheresa was listed as a victim of the ShinyHunters "pay or leak" extortion group . After the ransom deadline passed, the group publicly released the data which contained 84k unique email addresses. The exposed data also included names, phone numbers, physical addresses, purchases and partial credit card data including card type, last 4 digits and expiry date. The following data types were included in the breach: If you had an account with Mytheresa, take these steps immediately: Check if your account was affected at HaveIBeenPwned.com Watch for phishing emails that reference the breach or impersonate the affected company Contact your bank or card issuer to request a replacement card Review recent statements for unauthorized transactions Be alert for social engineering attempts using your exposed personal information Enable two-factor authentication on the affected service if available Consider using a password manager to generate unique passwords for each service Sherlock Forensics investigates data

When was this signal reported?

Shadow Tier lists Apr 12, 2026 as the signal date.

Which organization is connected to this signal?

Mytheresa is the organization connected to this public signal.

Explore Mytheresa
Which attack pattern is relevant?

This signal is connected to phishing and social-engineering intelligence based on its reported incident context.

Explore phishing and social-engineering intelligence
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence