Graff Gets Hit by Ransomware Attack
The data breach included some personal details of high-end clients.

Ransomware is malware that uses encryption to hold a victim’s system or personal files and demands payment to get them back.
For most people involved in the Graff data breach, it included details like their name and potentially their home address—which can be retrieved in the public domain from other sources– rather than any other confidential details that would put them at risk of identity theft.
A Graff spokesperson said the brand informed “the small group of individuals whose personal data was compromised to such an extent” and advised them on the appropriate steps to take.
The brand’s security systems alerted it to the activity, allowing it to react quickly and shut down its network.
Graff said it has been working with the U.K.’s Information Commissioner’s Office and relevant law enforcement on the incident.
“Thanks to our robust back-up facilities we were able to rebuild and restart our systems within days - crucially with no irretrievable loss of data,” the spokesperson said.
“Sadly, it appears that notable brands, corporations and even government departments are deliberately targeted by unscrupulous operators to extort money, cause disruption or simply embarrassment. Cybercrime continues to rise in scale and complexity. It is a threat to every business. Maintaining the highest level of security against these threats has always been a top priority for us. We are continually strengthening our systems to counter these threats as they evolve.”
The group known as Conti is said to be behind the attack, the U.K.’s The Times reported, leaking the details of the brand’s high-end clientele to the dark web.
In a September press release, the Cybersecurity and Infrastructure Security Agency said it and the Federal Bureau of Investigation had seen an increase in the use of Conti ransomware in more than 400 attacks on U.S. and international organizations.
Earlier this year, the FBI said it had identified at least 16 Conti ransomware attacks that targeted healthcare and first responder networks in the U.S.
While the hacks that tend to make headlines are the bigger ones, small businesses should also protect themselves against such crimes.
The Jewelers’ Security Alliance recommends the following actions to prevent cybercrime.
1. Have proper firewalls, anti-virus, and anti-malware for all systems, and keep them up to date.
2. Don’t let employees use company internet-connected devices at work for personal use or download software without permission. Additionally, don’t let them introduce personal memory sticks into a company system.
3. Have strong, unique passwords.
4. Beware of phishing. One of the main pathways for cyber criminals is to lead someone to open and click on a link in an email which will unleash malware to penetrate the system, JSA said.
So, don’t open or click on unknown or suspicious emails. Even emails from people and customers or vendors that might seem familiar can be spoof emails or from someone who has obtained an email address only slightly different from a real email address.
Additionally, look for unfamiliar foreign domains, misspellings, and other anomalies.
5. Beware of social engineering, which is obtaining confidential information by manipulating and/or deceiving people.
Criminals can obtain information on company personnel, customers, ordering, shipping procedures, payment methods, and other information for a fraudulent transaction through impersonation, email correspondence, research on social media, or other means.
So, be careful of the information provided to the public by email, website, social media, or phone.
Also, confirm the identity of the person to whom you are talking. If the interaction includes a transaction, call the known customer on the telephone to confirm there hasn’t been fraudulent impersonation.
6. Avoid visiting questionable and risky sites.
7. Don’t download questionable apps from obscure or unknown companies.
8. Have a written cyber security policy that employees must read and sign.
9. Have regular staff meetings and periodic reviews of cyber protocols for the business.
The Latest

The home improvement store’s website features an “Empowerment Tools” demi-fine jewelry collection.

The show will feature a new pavilion of 30 jewelry designers and manufacturers from Surat, India.

A government official said search crews “found the needle in the haystack” when they located the capsule belonging to Rio Tinto along an 870-mile stretch of road.

De Beers Institute of Diamonds provides the very best in diamond verification, education and diamond services.

Amanda Gizzi welcomes February with a selection of amethyst jewelry, a birthstone that “deserves its own time to shine.”


Behind the playful and nostalgic brand lies deeper meaning.

The Time Century Jewelry Center is located in downtown Miami’s jewelry district.

De Beers is sharing over 130 years of experience and expertise through the De Beers Institute of Diamonds with a selection of courses.

Wariness about the year ahead offset a more positive view of the current economic situation.

The IJO also welcomed one new vendor member to its 13-member board, Brecken Farnsworth of Parlé Jewelry Designs.

It begins with a “t” and ends with a “c” and is imbued with warmth and positivity, Peter Smith writes.

The tiny capsule, which is believed to have fallen out of a truck, was lost somewhere along an 870-mile stretch of desert road.

The jeweler’s expansion plans include 20 to 30 more stores in North America and the Middle East over the next two to three years.

The Italian luxury brand will receive the first Gem Award for High Jewelry Excellence.

Industry veteran Kevin Lane has stepped into the role.

The ancient Egyptian teenager was buried 2,300 years ago with 49 amulets to guide him through the afterlife.

The NRF’s annual survey shows that consumer attitudes about how, or even whether, to celebrate Feb. 14 continue to evolve.

Nominations are open now through March 24.

A column detailing how independent jewelers did last year and the top watch brands of 2022 were among the most-read stories last week.

Acquired in 2021, the brand’s high jewelry sales have doubled and its new “Lock” collection was an instant hit.

Executives from Fred Meyer Jewelers and Riddles Jewelers have filled the roles.

The Victorian-inspired design is a functional lock and key.

For over 100 years, JA New York has played an integral role in facilitating the evolution of our industry, while also honoring past traditions.

The trend forecaster and her guests explored unconventional jewelry designs, NFTs, AI art, and more during her Trendvision presentation.

The Emerging Designers Diamond Initiative provides diamond credit and mentorship to young brands helmed by BIPOC designers.

It will be located in San Antonio’s Alamo Quarry Market and will be Lee Michaels’ third location in the city.

Stephanie Gottlieb, Jewelers Mutual’s Mike Alexander, and Craig Rottenberg of Long’s Jewelers are among the new board members.