Fashion retail giant Victoria’s Secret has temporarily shut down its website and several in-store services as a precautionary measure following a security incident. The company, which operates approximately 1,380 retail stores across nearly 70 countries and reported annual revenue of $6.23 billion for the fiscal year ending February 2025, is currently working to restore operations.
“Valued customer, we identified and are taking steps to address a security incident. We have taken down our website and some in store services as a precaution,” reads a message now displayed on the company’s website.
A Victoria’s Secret spokesperson confirmed to BleepingComputer that the company has engaged external cybersecurity experts to investigate the incident’s impact. CEO Hillary Super informed employees that “Recovery is going to take awhile,” according to a note obtained by Bloomberg News.
While the nature of the security breach remains undisclosed, Victoria’s Secret has assured customers that its physical Victoria’s Secret and PINK stores remain open during the restoration process.
This incident follows a series of cyberattacks targeting major fashion and retail brands. French luxury brand Dior recently disclosed a cybersecurity breach affecting some of its Fashion and Accessories customers, while Adidas revealed a data breach after hackers compromised a customer service provider.
The retail sector has faced increasing cyber threats, with UK retailers including Harrods, Co-op, and Marks & Spencer suffering attacks in recent months. Marks & Spencer anticipates potential profit losses of up to £300 million ($402 million) due to sales and operational disruptions following its breach.
Google recently warned that the Scattered Spider threat group has expanded its ransomware and extortion operations to target U.S. retailers, though it remains unclear if this group is connected to the Victoria’s Secret incident.
