Data breach
Mytheresa
- Records
- 84,370
- Breach date
- 11 April 2026Estimated
- Added
- 23 April 2026
What was exposed
5 types of data
- Email addresses84,370
- Names61,428
- Phone numbers33,830
- Street addresses2,179
- Dates of birth1,641
About this breach
Mytheresa, the Munich-based luxury fashion e-commerce retailer, has been caught up in a mass data leak by the extortion group ShinyHunters. According to reporting by Cybernews, the group published data it claims to have stolen from Mytheresa on April 23, 2026, alongside stolen data from Zara, Carnival, 7-Eleven, and other companies. The hackers allegedly breached the retailer on April 12 and gave the company a deadline of April 14 to negotiate a ransom. When no deal was reached, the group dumped the data and said it would keep it online indefinitely. Our investigation team estimates the indexed dataset contains 84,370 records and added the listing to our database on April 23, 2026, with an estimated attack date of April 11, 2026. The hackers' own claim puts the breach a day later. Mytheresa had not commented on the incident in detail as of the reporting by German outlet it-daily.net on April 23, 2026.
Breach Timeline
April 12, 2026: ShinyHunters listed Mytheresa as a victim and claimed to have breached the company, according to Cybernews.
April 14, 2026: The group's deadline for Mytheresa to negotiate a ransom passed, per Cybernews reporting.
April 23, 2026: ShinyHunters published the stolen Mytheresa data along with data from roughly 40 victims, including Zara, Carnival, and 7-Eleven, as reported by Cybernews and TechRadar.
What Information Was Compromised?
Our analysis found the following data types in this breach: 84,370 email addresses, 61,428 names, 33,830 phone numbers, 2,179 street addresses, and 1,641 birth dates. Cybernews reported that the hackers claimed the stolen data also included sensitive customer personal information and transactional history. The group reportedly warned the retailer that customer records and purchase histories would be published unless a ransom was paid.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Email addresses, names, and phone numbers in combination are the raw material for targeted phishing. Scammers can use this data to send convincing messages that appear to come from Mytheresa, a delivery service, or a bank, referencing real customer details to build trust. Phone numbers open the door to smishing, which is phishing by text message, and to fraudulent calls.
Street addresses and birth dates make social engineering more convincing. Someone with this data could pose as customer support, a courier, or a fraud investigator and sound credible because they know personal details. For a luxury retailer, transactional history can reveal spending patterns and financial circumstances, which fraudsters can use to tailor their approaches. Customers whose full payment details were not exposed should still watch for any communication that tries to trick them into revealing card numbers or login credentials.
What Should You Do If You Were Affected?
Be skeptical of unexpected emails, texts, or calls that mention Mytheresa, your purchases, or your personal details. Do not click links or share codes, passwords, or card details.
If you have a Mytheresa account, change your password and enable two-factor authentication if it is offered. If you reused that password elsewhere, change it there too.
Watch your bank and card statements for unfamiliar charges and report anything suspicious to your bank quickly.
Treat any email about "account problems" or "order issues" as unverified. Go to the Mytheresa website directly by typing the address yourself rather than following a link.
Consider being alert to mail or phone scams that reference your address, since street addresses appear in the leaked data.
In the news
- Cybernews: ShinyHunters dumps Mytheresa, Zara, Carnival datacybernews.com (opens in a new tab)
- TechRadar: ShinyHunters exposes data on Mytheresa, Zara, Carnival, 7-Eleventechradar.com (opens in a new tab)
- it-daily.net: Zara, Mytheresa und 7-Eleven: ShinyHunters leakt Millionen Kundendatenit-daily.net (opens in a new tab)
