Graff Gets Hit by Ransomware Attack
The data breach included some personal details of high-end clients.
Ransomware is malware that uses encryption to hold a victim’s system or personal files and demands payment to get them back.
For most people involved in the Graff data breach, it included details like their name and potentially their home address—which can be retrieved in the public domain from other sources– rather than any other confidential details that would put them at risk of identity theft.
A Graff spokesperson said the brand informed “the small group of individuals whose personal data was compromised to such an extent” and advised them on the appropriate steps to take.
The brand’s security systems alerted it to the activity, allowing it to react quickly and shut down its network.
Graff said it has been working with the U.K.’s Information Commissioner’s Office and relevant law enforcement on the incident.
“Thanks to our robust back-up facilities we were able to rebuild and restart our systems within days - crucially with no irretrievable loss of data,” the spokesperson said.
“Sadly, it appears that notable brands, corporations and even government departments are deliberately targeted by unscrupulous operators to extort money, cause disruption or simply embarrassment. Cybercrime continues to rise in scale and complexity. It is a threat to every business. Maintaining the highest level of security against these threats has always been a top priority for us. We are continually strengthening our systems to counter these threats as they evolve.”
The group known as Conti is said to be behind the attack, the U.K.’s The Times reported, leaking the details of the brand’s high-end clientele to the dark web.
In a September press release, the Cybersecurity and Infrastructure Security Agency said it and the Federal Bureau of Investigation had seen an increase in the use of Conti ransomware in more than 400 attacks on U.S. and international organizations.
Earlier this year, the FBI said it had identified at least 16 Conti ransomware attacks that targeted healthcare and first responder networks in the U.S.
While the hacks that tend to make headlines are the bigger ones, small businesses should also protect themselves against such crimes.
The Jewelers’ Security Alliance recommends the following actions to prevent cybercrime.
1. Have proper firewalls, anti-virus, and anti-malware for all systems, and keep them up to date.
2. Don’t let employees use company internet-connected devices at work for personal use or download software without permission. Additionally, don’t let them introduce personal memory sticks into a company system.
3. Have strong, unique passwords.
4. Beware of phishing. One of the main pathways for cyber criminals is to lead someone to open and click on a link in an email which will unleash malware to penetrate the system, JSA said.
So, don’t open or click on unknown or suspicious emails. Even emails from people and customers or vendors that might seem familiar can be spoof emails or from someone who has obtained an email address only slightly different from a real email address.
Additionally, look for unfamiliar foreign domains, misspellings, and other anomalies.
5. Beware of social engineering, which is obtaining confidential information by manipulating and/or deceiving people.
Criminals can obtain information on company personnel, customers, ordering, shipping procedures, payment methods, and other information for a fraudulent transaction through impersonation, email correspondence, research on social media, or other means.
So, be careful of the information provided to the public by email, website, social media, or phone.
Also, confirm the identity of the person to whom you are talking. If the interaction includes a transaction, call the known customer on the telephone to confirm there hasn’t been fraudulent impersonation.
6. Avoid visiting questionable and risky sites.
7. Don’t download questionable apps from obscure or unknown companies.
8. Have a written cyber security policy that employees must read and sign.
9. Have regular staff meetings and periodic reviews of cyber protocols for the business.
The Latest
The jeweler’s latest high jewelry collection looks into the Boucheron archives to create a “living encyclopedia of high jewelry.”
Watch and jewelry sales slipped 3 percent in 2024, though the luxury conglomerate did see business pick up in the fourth quarter.
Olivier Kessler-Gay will take over the role on March 3.
The new year feels like a clean slate, inspiring reflection, hope, and the motivation to become better versions of ourselves.
It hit a four-month low in January due to concerns about the job market, though consumers remain bullish about the stock market.
The jewelry designer and master metalsmith will present on the ancient Japanese metalworking technique at the Atlanta Jewelry Show in March.
The “Moments” social media campaign emphasizes the emotional ties between natural diamonds and life’s special milestones.
A Diamond is Forever hosted a holiday celebration in honor of their new marketing campaign, ‘Forever Present.’
The versatile “As We Are” collection features 14 pieces with interlocking designs allowing for 27 different looks worn around the body.
Letsile Tebogo will help to promote natural diamonds and the good they have done for his country.
The showcase, in its second year, will feature more than 20 international brands at its curated event from Feb. 2-4.
“My Next Question” guests Sherry Smith and Edahn Golan share their 2025 forecasts, from sales and marketing to what retailers should stock.
The seminar series covers topics from market trends and colored stone terminology to working with museums and growing an Instagram profile.
LeVian is remembered for his leadership in the jewelry industry and for being a selfless and compassionate person.
Jemora Gemhouse’s inaugural auction, slated for March, will take place in Dubai and feature polished sapphires.
Quinn partnered with Gemfields to create “Crazy Love,” which features Zambian emeralds and Mozambican rubies across 10 pieces.
The catalog is 48 pages and features more than 100 styles.
The one-of-a-kind necklace was designed in celebration of the Chinese New Year, as 2025 is the Year of the Snake.
The gemstone show is slated to take place at the Scottish Rite Cathedral.
From raffles to auctions to donations, the industry is working to aid charities in Los Angeles amid the raging wildfires.
Francis “Gosh” Eiseb, 58, was a senior protection officer for Namib Desert Diamonds, also known as Namdia, in Windhoek, Namibia.
The online diamond and jewelry marketplace has expanded, introducing a new platform dedicated to colored gemstone trading.
The second annual learning forum for retailers is slated for March 13 at City Winery in Pier 57 in New York City.
Roy Safit took over the role on Jan. 1.
Sherry Smith shares data on the year gone by, including the breakdown between natural and lab-grown diamond sales.
The company also is matching donations made to Jewelers of America and the Diamond Council of America’s Jewelers Relief Fund.
Now in its fourth year, the program is expanding to include a list of “20 Under 40” for jewelry suppliers.