← Back to timeline

Mytheresa

SourceHave I Been Pwned
StatusConfirmed breach
AddedMay 27, 2026
OccurredApril 12, 2026
Accounts affected84,108
Domainmytheresa.com
All Mytheresa breaches →
What was exposed
Email addressesNamesPartial credit card dataPhone numbersPhysical addressesPurchasesSalutations
What to do if you were affected
Worried your data is exposed?Take back control of your personal data with Literal.
Protect your data
Details
In April 2026, the luxury fashion e-commerce platform Mytheresa was listed as a victim of the ShinyHunters "pay or leak" extortion group . After the ransom deadline passed, the group publicly released the data which contained 84k unique email addresses. The exposed data also included names, phone numbers, physical addresses, purchases and partial credit card data including card type, last 4 digits and expiry date.
Frequently asked questions

What is the Mytheresa data breach?

In April 2026, the luxury fashion e-commerce platform Mytheresa was listed as a victim of the ShinyHunters "pay or leak" extortion group . After the ransom deadline passed, the group publicly released the data which contained 84k unique email addresses. The...

When did the data breach happen?

This data breach occurred around April 2026.

How many accounts were affected?

Around 84,108 accounts were affected.

What information was exposed?

Exposed data included Email addresses, Names, Partial credit card data, Phone numbers, Physical addresses, Purchases and Salutations.

What should I do if I was affected?

Watch your card and bank statements for unfamiliar charges, and consider requesting a new card number. Expect more phishing and spam at this address. Treat messages that reference this company with extra caution. Watch for text-message phishing and SIM-swap attempts on your phone number. Be wary of targeted scams that use your personal details to sound convincing.

View the original record on Have I Been Pwned ↗
Related breaches