Our 2026 Luxury Sector Analysis [Threat Note]

Between January and September 2026, CybelAngel’s threat intelligence analysts tracked 467 claims against the luxury sector. That is up 75% from 267 in the same period of 2025, against a 51% rise across all sectors. Yet their analysis shows almost none of that growth reached the maisons: breach claims naming a prestige maison fell from 14 to 4.

What did reach the maisons came through the brand itself, month after month, with no conflict or campaign to drive it. Across CybelAngel’s client monitoring, our analysts found counterfeiting, payment fraud and impersonation to be the most frequent and most persistent exposure. All three run on one shared underground infrastructure, with Telegram foremost.

This post is a condensed version of the Luxury Sector Threat Landscape 2026 report and the full report is available on request.

It breaks down claim volumes by attack type, subsector and victim geography, the ransomware and data extortion actors active in scope, the four supplier pathways through which brand data was exposed, and the underground channels that carry counterfeiting, payment fraud and impersonation.

Why luxury draws sustained attention

The three largest ransomware operators directed between 1.1% and 2.5% of their 2026 claims at luxury, and only one actor in scope concentrated on the sector, on a base of 8 claims. Brand and customer abuse, by contrast, showed no decline across the monitoring year. CybelAngel’s analysts link that persistence to five characteristics of the sector.

  • A global reputation. Criminals exploit the brand without ever touching the maison’s own systems.
  • Organised scarcity. Restricted allocation and waitlists leave genuine demand unserved, and counterfeiters fill exactly that space.
  • A high-net-worth, socially identifiable customer base. Luxury customer data carries a resale premium over an equivalent retail base.
  • An accessible entry price. Fragrance and cosmetics widen the pool of potential victims well beyond actual clients.
  • Value built on exclusivity, not material cost. Each counterfeit in circulation erodes the brand’s premium, not just the one sale it displaces.

Geography follows function rather than goods. Most of the e-commerce and shopping-agent platforms we identified for counterfeit distribution are China-based or source from Chinese wholesale listings. Payment and account fraud runs through forums and marketplaces most commonly associated with Russia.

Counterfeiting is the highest-volume exposure

Counterfeit and replica distribution generated more cases than any other category across our luxury portfolio. It is also the most structurally diverse, and each product category follows its own logic.

The pattern matches global customs data. The OECD and EUIPO’s Mapping Global Trade in Fakes 2025 values counterfeit trade at USD 467 billion in 2021. Clothing, footwear and leather goods made up 62% of seized fakes, and China was the source of 45% of seizures.

  • Perfumes carry the highest volume by case count, concentrated on maisons with a significant fragrance line. Catalogues blend outright fakes, openly marketed dupes and testers.
  • Clothing is driven by sheer brand recognition more than scarcity.
  • Bags follow deliberate scarcity. Where allocation is restricted, counterfeiters sell into the unmet demand.
  • Jewellery and watches appear far less often, though dedicated storefronts confirm the channel exists.

A related activity sits alongside: the resale of goods sold as genuine but obtained through theft or warehouse diversion.

Distribution spans five tiers of platform: large, mostly legitimate marketplaces; shopping-agent services that buy straight from Chinese wholesale listings; single-purpose counterfeit storefronts; Tor marketplaces; and social media sales, often dropshipped from an undisclosed supplier. Each tier differs in scale, detection difficulty and takedown feasibility. Takedown works cleanly against a domain or a listing, but does little against a vendor whose reputation and client base outlive any single storefront.

Fraud against the maison is sold as a package

Unauthorised purchases against a maison’s e-commerce rely on one of two things: a payment method that isn’t the buyer’s, or a document convincing enough to force a refund. Fraud communities document and sell the mechanisms for both, including refund-as-a-service schemes, BIN-based card fraud, carding guides and fabricated invoices. None of them is specific to luxury.

Sellers now bundle these elements. One “starter bundle” advertised on Telegram combined BINs, stolen card data and full identity profiles with OTP bypass scripts and ongoing seller support. It listed merchant-specific methods for luxury maisons side by side with methods for unrelated, non-luxury retailers.

The losses land directly on margin, in three forms: merchandise shipped and never recovered, chargebacks absorbed after a lost dispute, and stricter refund policies that add friction for genuine customers. The first two are imposed by the fraud. The third is a choice the maison makes, which makes it the one cost worth deciding on deliberately rather than letting it drift with each fraud cycle.

Impersonation reaches people who never bought from the brand

A maison’s name builds trust on its own, even with people who have no relationship with the brand. Criminals exploit that trust in two main ways.

Fraudulent investment platforms on Telegram borrow a maison’s name and circulate fabricated proof-of-withdrawal screenshots. They run small-deposit, fixed-return schemes whose appeal rests entirely on brand-signalled wealth the victim cannot verify. Recruitment scams work the same asset from another angle: a fake job listing impersonates the maison, then funnels applicants to a fake login page or a request for banking details framed as onboarding.

The FBI has documented a close variant in which scammers pose as recruiters for legitimate businesses and require cryptocurrency payments to unlock work, through a fake interface that shows earnings victims can never withdraw.

Both leave the maison carrying reputational risk toward a population it can neither identify nor warn. In most cases, the brand learns a scheme existed only after victims have lost money to it.

Commodity retail fraud runs alongside. Compromised customer accounts sell on Telegram, resold customer databases feed phishing built on real order history, and gift cards, vouchers and loyalty points circulate as a further cash-out channel.

Exposure tracks accessibility, not prestige

Brand abuse follows a gradient across a luxury group rather than hitting every maison the same way. Gift-card resale, account takeover, carding and refund abuse need transaction volume to pay off at scale. They concentrate on a group’s accessible, high-volume maisons, where a gift-card or loyalty programme meets a broad customer base.

The more exclusive the maison, the less volume it offers, and the more its exposure shifts to impersonation. Investment scams, fake recruitment and lookalike channels trade on the name itself, because the name is the only asset worth exploiting. Two maisons in the same group can therefore face very different threats, and need watching on very different channels.

Attack claims rose, but the maisons were not the target

The 75% rise in claims against the sector has two drivers, and neither selects luxury. Outside the Middle Eastern conflict theatres, the sector grew 41%, below the 51% global trend.

Hacktivist defacement followed the conflict calendar. Defacement claims rose from 33 to 139 in two steps: after the US-Israel strikes on Iran on 28 February, and after the ceasefire collapsed in early July. August’s 37 claims were the largest month of either year. The UAE, Iran, Israel and Saudi Arabia rose from 4 to 82 defacement claims, almost all against salons, perfumeries, jewellers and tailors on national target lists.

Access sales hit the same storefronts. Listings of access to luxury targets rose from 13 to 57, and 41 of them were CMS admin, web shell or site panel access to small shops. Defacement and access sales together account for 150 of the 200 additional claims. No access listing named a major maison.

Ransomware held flat and moved down the supply chain. Volumes barely moved (104 to 109), but the cast changed. CL0P and RansomHub are gone from the sector, and The Gentlemen now leads with 20 claims against textile mills and jewellery manufacturers in 13 countries, ahead of Qilin (11) and akira (10).

Supplier exposure gave the earliest warning. Brand data exposed through suppliers followed four pathways: access kept by former vendors, live SaaS integrations, client data copies held by processors, and the design and production chain. The SaaS pathway includes help desk voice phishing of the kind Google tracks as UNC6040, where callers talk staff into authorising a malicious connected app. In one case, customer data stolen from a payment processor was reposted by five other actors within four months, while the brand itself reported no breach. In another, a vendor’s breach listing preceded brand-level posts by about 10 weeks, while the brand’s own perimeter showed nothing.

Event-driven pressure fades, brand pressure stays

Pressure on a maison’s infrastructure is event-driven and 2026 growth traces to a conflict, to mass exploitation of storefront software and to a handful of vendor intrusions, all of which can resolve through patching, containment or de-escalation.

Pressure on the brand is also standing. Our analysis shows that brand and customer abuse showed no sign of decline across the monitoring year, and the same underground economy that resells counterfeits and fraud bundles also resells breached customer data. An apparent drop would more likely reflect reduced visibility than reduced activity.

The full Luxury Sector Threat Landscape 2026 report includes the complete actor breakdown, the four supplier pathways with the checks that surface each one, and monitoring priorities matched to each exposure and maison profile.

About the author