Ransomware victim disclosure
← All victimsRalph Lauren
Claimed by Shinyhunters · listed 4 hours ago
Status timeline
- ListedJun 16, 2026
- Data leakeddate unknown
At a glance
- Group
- Shinyhunters
- Status
- Data leaked
- Country
- United States
- Sector
- Consumer Services
- Listed on leak site
- Jun 16, 2026
About the victim
AI dossier — public-source company profileRalph Lauren is a global luxury fashion company known for designing, marketing, and selling high-end clothing, accessories, and lifestyle products. The company operates retail locations and e-commerce channels worldwide, serving affluent consumers.
- Industry
- Luxury Fashion & Apparel
Attack summary
Severity: critical — Confirmed exfiltration of regulated PII at significant scale (220GB+) plus financial transaction data and proprietary business information. Impacts millions of customers and represents material business harm.ShinyHunters claims to have exfiltrated over 220GB of data from Ralph Lauren, including customer personally identifiable information (PII), purchase and transaction records, and proprietary product design information for unreleased collections through 2027. The group states the company declined to negotiate.
Data the group says was taken
AI dossier — extracted from the leak post- customer PII
- purchase history
- transaction records
- unreleased product designs (2027+)
What the group claims
Over 220GB of data containing customer PII, purchase/trasnaction info, future unreleased releases from 2027 and onward, and more was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. | Size: 163GB+ (compressed) | Updated: 16 June 2026 | SHA256: 17a7af9c00ea38ce822e2f022c0ceb5149535610a15f009b866d616e70cbf7e2
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

