INDEX / DIRECTORY / DIOR / DIGITAL

Dior DIGITAL

DIGITAL INFRASTRUCTURE AUDIT UPDATED 2026-07-04
Digital Score 0.20 /10 D Dior - BDS-1000 276
Digital 0.20

Evidence-only forensic audit. Scoring happens downstream - see the main dossier for the composite assessment.

Forensic audits like this are reader-funded - no sponsors, no ads. Support OpenIntel →

Digital Domain Audit: Christian Dior (Dior)

Target: Christian Dior Couture (luxury fashion/fragrance house; brand of LVMH) Domain: Digital (Digital / Technology) Date: June 2026 Scope: Dior the fashion house’s own digital/data/cyber/surveillance/AI conduct re Israel. LVMH group-level tech is attributed at the parent-group level.

Scope note. This audit assesses Christian Dior Couture and Parfums Christian Dior (the “Dior” maison) and its own digital, data, cyber, surveillance and AI conduct, with a focus on any Israel nexus. The parent LVMH group’s enterprise technology programme (e.g. the LVMH–Google Cloud partnership) and the Arnault family holding / Aglaé Ventures investment activity are separate legal and operational layers and are treated below only as explicitly flagged parent/holding-level context. US- and EU-domiciled vendors are treated as such even where founders have Israeli backgrounds; only the vendor’s corporate domicile and the Dior-specific contracting relationship are assessed as in-scope.

Enterprise Technology Stack & Vendor Relationships

Dior’s client data is managed through a third-party Salesforce CRM environment, which was confirmed as the platform compromised in the 2025 breach campaign described below.12 Dior had been operating the affected customer-management SaaS system since 2020.3

For AR beauty and virtual try-on, Parfums Christian Dior contracts Perfect Corp (a beauty-tech firm headquartered in New Taipei City, Taiwan, with a New York presence; founded 2014 by Alice Chang), a relationship running since 2020 and spanning the Dior website, retailer sites, Google platforms, WeChat and the Taobao Mini Program.45 A 2022–2023 live-consultation offering paired Perfect Corp’s AR try-on with live-shopping vendor Bambuser (a 2021 LVMH Innovation Award winner).46 Dior’s eyewear “Try Online” virtual try-on used facial-recognition technology supplied by FittingBox, a virtual-fitting company headquartered in Toulouse, France (with a US base in Miami).78 None of Perfect Corp, Bambuser or FittingBox is Israeli-domiciled.

The most material Israel-nexus vendor relationship in Dior’s own stack is with Kahoona, an Israeli AI personalisation startup. Kahoona was founded by Technion/MIT graduates Gal Rapoport, Alon Ashkenasi and Ohad Tzur, operates its R&D centre in Tel Aviv (with a US sales base in San Diego), and is listed as an Israeli company on Startup Nation Central’s Finder.910 Kahoona collaborated directly with the Dior team through LVMH’s startup programme; its CEO described working “together as real partners” with Dior, and Christian Dior Couture was awarded the Best Business Prize for its collaboration with Kahoona at the 2025 Viva Technology / 9th LVMH Innovation Award.911 Kahoona’s platform generates anonymised, cookieless real-time user profiles (“digital body language”) to personalise interactions for anonymous website visitors.911 This is a Dior-specific contracting relationship with an Israeli-domiciled technology vendor, not merely a group-level arrangement.

In Israel itself, the Dior e-commerce storefront (diorboutique-il.com) is operated by DRRR Ltd, the exclusive Israeli distributor of Parfums Christian Dior, and runs on the Shopify platform.1213 This is a local-distributor storefront rather than Christian Dior Couture’s own corporate e-commerce, a distinction relevant to attributing data-processing conduct.

Parent-group context: At the LVMH group level, LVMH and Google Cloud formed a strategic AI/cloud partnership (announced June 2021), under which cloud-based AI underpins group operations and LVMH modernised IT infrastructure on Google Cloud.14 This is a parent-group arrangement, not a Dior-maison-specific contract, and is attributed accordingly.

Surveillance, Biometrics & Retail Technology

Dior operated an eyewear virtual try-on tool (“Try Online” on dior.com) that, per a class-action complaint, used FittingBox facial-recognition software to scan users’ facial geometry to overlay eyewear.7 An Illinois suit filed 30 August 2022 alleged Dior collected this biometric data without the knowledge, consent, written authorisation or published retention policy required by the Illinois Biometric Information Privacy Act (BIPA).7 The suit was dismissed on 10 February 2023, the court ruling Dior’s conduct fell within BIPA’s healthcare exemption (treating non-prescription sunglasses as Class I medical devices).7 This establishes that Dior’s own consumer-facing tools captured biometric facial-geometry data; the supplying vendor (FittingBox) is French, not Israeli.

Dior states it uses video surveillance in its stores to detect security/safety incidents, shoplifting and other illegal activity.15 For in-boutique retail technology, Dior is documented using NFC authentication tags on products and participates in luxury-sector clienteling (orchestrating boutique, web and aftersales touchpoints into unified customer profiles).16

On in-store facial-recognition or biometric customer-tracking specifically by Dior in Israel or anywhere: No public evidence identified. On any Israeli-origin biometric, surveillance or video-analytics vendor in Dior’s own retail-technology stack: No public evidence identified.

Cloud Infrastructure, Data Residency & Sovereign Cloud Participation

On Dior maison-specific cloud arrangements: the breached client data sat in a third-party Salesforce environment.12 At the LVMH group level (attributed at parent-group level), infrastructure runs partly on Google Cloud.14

On any Dior-specific data-residency arrangement, data centre, or sovereign/government-cloud participation in Israel: No public evidence identified. The Israeli Dior storefront is a Shopify-hosted distributor site (DRRR Ltd), with no public indication of Dior-Couture-controlled data residency in Israel.1213 Dior is not publicly identified as a participant in Israel’s “Nimbus” government cloud programme or any equivalent.

Defence, Intelligence & Security Sector Technology Relationships

On any relationship between Dior (the fashion house) and defence, military, intelligence or security-sector technology - Israeli or otherwise: No public evidence identified. Dior is a luxury fashion/fragrance house with no identified defence or intelligence technology supply, procurement or partnership in the public record.

Parent/holding-level context: The Arnault family / Aglaé Ventures investment vehicle (a holding-level entity, not Dior the maison) participated in funding for the Israeli cloud-security firm Wiz.17 This is an Arnault holding-company investment, distinct from Christian Dior Couture’s own operations, and is recorded here as context, attributed to the Arnault holding level.

AI, Algorithmic & Autonomous Systems

Dior deploys AI across personalisation, virtual try-on, demand forecasting and trend prediction, building “detailed, dynamic customer profiles” from browsing behaviour, purchase history and social-media engagement to drive tailored recommendations.1819 Dior’s AI posture is described as a “dual-engine” of the maison’s own implementations plus the LVMH technology ecosystem.19

The AI/algorithmic system with the clearest Israel nexus is the Kahoona personalisation engine (Israeli vendor; Tel Aviv R&D), which Dior used to profile anonymous website visitors’ “digital body language” in real time - an award-winning Dior–Kahoona collaboration (2025 LVMH Innovation Award, Best Business Prize).911 AR/AI beauty personalisation is also delivered via Taiwan’s Perfect Corp.45

On any autonomous systems or AI deployed by Dior in a military, security or occupation context: No public evidence identified.

Technology Ecosystem & R&D Footprint

Dior engages emerging technology vendors primarily through La Maison des Startups LVMH, the group accelerator, where Dior has piloted external startups including the Israeli firm Kahoona (personalisation) and the London-based 3D/AR firm Threedium (3D product visualisation; founded 2017, London-HQ, non-Israeli founders).91120 Of Dior’s publicly documented startup/tech collaborations, Kahoona is the one with Israeli R&D and corporate roots; Perfect Corp (Taiwan), Bambuser, FittingBox (France) and Threedium (UK) are not Israeli.47920

On a Dior-operated R&D centre, innovation lab or engineering presence physically located in Israel: No public evidence identified. Dior’s documented Israeli footprint is commercial retail (Tel Aviv and Jerusalem boutiques, the latter at Mamilla Mall) operated with local partners/distributors, not technology R&D.2112

Civil Society Scrutiny & Regulatory History

2025 Salesforce/ShinyHunters breach. Dior was among numerous LVMH and luxury brands hit in a 2025 social-engineering campaign against Salesforce environments, attributed by Google’s Threat Intelligence Group to the actor it tracks as UNC6040, widely linked to the ShinyHunters extortion group.122 At Dior, an unauthorised party accessed a client database; the intrusion occurred 26 January 2025, was discovered 7 May 2025, and US customer notifications were sent from mid-July 2025, with separate notices in South Korea and China.23 Exposed data included names, contact details, mailing addresses, dates of birth, purchase history and, in some cases, government-issued ID numbers; Dior said no payment/bank data was in the affected database.23 Over 100,000 US records were reported, and Korean regulators put the figure at roughly 1.95 million customers there.323

South Korea PIPC enforcement. South Korea’s Personal Information Protection Commission fined Dior approximately US$9.4 million (announced 13 February 2026) for security failures - no access allow-lists, no bulk-download restrictions, no access-log inspection - and for breaching notification rules, including failure to report to the Korea Internet & Security Agency (KISA) as required.23 The action was part of a combined ~US$25 million in fines across Louis Vuitton, Dior and Tiffany.2324

US litigation. Data-breach class actions tied to the Salesforce hack were reported, with at least some claims against Dior dismissed.25

BIPA biometric suit. As noted, the Illinois BIPA suit over Dior’s FittingBox-powered eyewear try-on was filed in August 2022 and dismissed in February 2023.7

Israel-related brand scrutiny. In November 2023 Dior faced pro-Palestinian boycott calls after selecting Israeli model May Tager for a campaign; coverage noted the framing that Dior “replaced” Bella Hadid was inaccurate, as Hadid’s Dior Makeup contract had ended in 2022.26 This is reputational/brand-campaign scrutiny rather than a digital/technology matter, and is more properly assessed in the Political domain; it is noted here only for completeness of the public-scrutiny record.

On civil-society or regulatory scrutiny of Dior’s digital/technology conduct specifically tied to Israel (e.g. surveillance tech, Israeli-vendor data flows): No public evidence identified beyond the Kahoona vendor relationship documented above, which has not itself been the subject of public scrutiny.

End Notes

Footnotes

  1. https://socradar.io/blog/salesforce-data-breach-affecting-multiple-companies/ 2 3

  2. https://www.bleepingcomputer.com/news/security/dior-begins-sending-data-breach-notifications-to-us-customers/ 2 3 4

  3. https://www.bleepingcomputer.com/news/security/louis-vuitton-dior-and-tiffany-fined-25-million-over-data-breaches/ 2 3 4

  4. https://www.happi.com/breaking-news/perfect-corp-partners-with-parfums-christian-dior/ 2 3 4

  5. https://en.wikipedia.org/wiki/Perfect_Corp 2

  6. https://www.pymnts.com/news/retail/2022/bambuser-collabs-with-perfect-corp-to-advance-virtual-try-on-with-christian-dior/

  7. https://www.classaction.org/news/dior-collected-illinois-residents-biometric-info-through-try-online-tool-lawsuit-says 2 3 4 5 6

  8. https://fittingbox.com/en/glasses-virtual-try-on

  9. https://www.ainvest.com/news/lvmh-ai-driven-luxury-innovation-ecosystem-strategic-startups-key-dominance-tech-enabled-luxury-2506/ 2 3 4 5 6

  10. https://finder.startupnationcentral.org/company_page/kahoona

  11. https://www.prnewswire.com/news-releases/privacy-focused-data-generation-platform-kahoona-raises-4-5-million-seed-round-led-by-global-founders-capital-301536593.html 2 3 4

  12. https://diorboutique-il.com/pages/about-us-1 2 3

  13. https://www.linkedin.com/company/drrr-dior-parfums-israel 2

  14. https://www.prnewswire.com/news-releases/lvmh-and-google-cloud-create-strategic-partnership-for-ai-and-cloud-based-innovation-301313307.html 2

  15. https://www.dior.com/en_us/fashion/personal-data

  16. https://rfid-pro.com/how-nfc-tags-work-in-dior-products/

  17. https://www.timesofisrael.com/luxury-goods-magnate-bernard-arnault-invests-in-israeli-cybersecurity-firm-wiz/

  18. https://digitaldefynd.com/IQ/christian-dior-using-ai-case-study/

  19. https://www.klover.ai/dior-ai-strategy-analysis-of-dominance-in-luxury-fashion-ai/ 2

  20. https://www.businesswire.com/news/home/20220114005058/en/Threedium-Joins-La-Maison-des-Startups-LVMH 2

  21. https://www.israelhayom.com/2020/06/12/dior-set-to-launch-flagship-boutique-in-jerusalems-mamilla-mall/

  22. https://www.computerweekly.com/feature/ShinyHunters-Salesforce-cyber-attacks-explained-What-you-need-to-know

  23. https://www.thefashionlaw.com/dior-data-breach-deal-signals-broader-cyber-risk-for-luxury/ 2 3

  24. https://www.rescana.com/post/louis-vuitton-dior-and-tiffany-fined-25-million-for-saas-customer-management-data-breaches-in-sou

  25. https://www.thefashionlaw.com/dior-dodges-data-breach-lawsuits-tied-to-salesforce-hack/

  26. https://www.haaretz.com/israel-news/2023-11-08/ty-article/.premium/pro-palestinian-activists-call-for-boycott-after-israeli-model-is-chosen-for-dior-campaign/0000018b-af36-dea2-a9bf-ffbe3be30000