Ransomware victim disclosure
← All victimsRalph Lauren Corporation
Claimed by Shinyhunters · listed 4 days ago
Status timeline
- ListedJun 11, 2026
- Data leakeddate unknown
At a glance
- Group
- Shinyhunters
- Status
- Data leaked
- Country
- United States
- Sector
- Consumer Services
- Listed on leak site
- Jun 11, 2026
About the victim
AI dossier — public-source company profileRalph Lauren Corporation is a global luxury fashion company known for clothing, accessories, and lifestyle products bearing the Ralph Lauren brand. The company operates retail and wholesale channels internationally.
- Industry
- Luxury Fashion & Apparel
Attack summary
Severity: critical — Confirmed exfiltration of customer PII and financial transaction data at scale (220GB+); regulated personal and financial information exposure affects potentially millions of customers.ShinyHunters claims to have exfiltrated over 220GB of data including customer personally identifiable information, purchase and transaction records, and unreleased product designs spanning 2027 onwards. The group issued a final extortion deadline of 14 June 2026.
Data the group says was taken
AI dossier — extracted from the leak post- customer PII
- purchase history
- transaction records
- unreleased product designs (2027+)
What the group claims
Over 220GB of data containing customer PII, purchase/trasnaction info, future unreleased releases from 2027 and onward, and more was compromised. This is a final warning to reach out by 14 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 11 June 2026 | Warning: FINAL WARNING
Source
Indexed 4 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

