The retailer is notifying customers it believes may have been affected, and is in the process of telling the relevant legal and privacy authorities.
Since discovering the breach, Kathmandu said it's confirmed the online store remains secure and that the wider IT network hasn't been impacted. The shares fell 0.8 per cent to $2.42.
"Whilst the independent forensic investigation is ongoing, we are notifying customers and relevant authorities as soon as practicable," chief executive Xavier Simonet said in a statement.
"As a company, Kathmandu takes the privacy of customer data extremely seriously and we unreservedly apologise to any customers who may have been impacted."
Kathmandu's admission comes the same day Parliament's justice select committee reported back on the Privacy Bill, which will update legislation governing data breaches and empowers the Privacy Commissioner to issue compliance notices when the new law is enacted.
Among the changes in the report, the committee, chaired by Labour MP Raymond Huo, decided to raise the threshold needed for a notifiable privacy breach to one where it's likely to cause serious harm rather than harm.