Graff Gets Hit by Ransomware Attack
The data breach included some personal details of high-end clients.

Ransomware is malware that uses encryption to hold a victim’s system or personal files and demands payment to get them back.
For most people involved in the Graff data breach, it included details like their name and potentially their home address—which can be retrieved in the public domain from other sources– rather than any other confidential details that would put them at risk of identity theft.
A Graff spokesperson said the brand informed “the small group of individuals whose personal data was compromised to such an extent” and advised them on the appropriate steps to take.
The brand’s security systems alerted it to the activity, allowing it to react quickly and shut down its network.
Graff said it has been working with the U.K.’s Information Commissioner’s Office and relevant law enforcement on the incident.
“Thanks to our robust back-up facilities we were able to rebuild and restart our systems within days - crucially with no irretrievable loss of data,” the spokesperson said.
“Sadly, it appears that notable brands, corporations and even government departments are deliberately targeted by unscrupulous operators to extort money, cause disruption or simply embarrassment. Cybercrime continues to rise in scale and complexity. It is a threat to every business. Maintaining the highest level of security against these threats has always been a top priority for us. We are continually strengthening our systems to counter these threats as they evolve.”
The group known as Conti is said to be behind the attack, the U.K.’s The Times reported, leaking the details of the brand’s high-end clientele to the dark web.
In a September press release, the Cybersecurity and Infrastructure Security Agency said it and the Federal Bureau of Investigation had seen an increase in the use of Conti ransomware in more than 400 attacks on U.S. and international organizations.
Earlier this year, the FBI said it had identified at least 16 Conti ransomware attacks that targeted healthcare and first responder networks in the U.S.
While the hacks that tend to make headlines are the bigger ones, small businesses should also protect themselves against such crimes.
The Jewelers’ Security Alliance recommends the following actions to prevent cybercrime.
1. Have proper firewalls, anti-virus, and anti-malware for all systems, and keep them up to date.
2. Don’t let employees use company internet-connected devices at work for personal use or download software without permission. Additionally, don’t let them introduce personal memory sticks into a company system.
3. Have strong, unique passwords.
4. Beware of phishing. One of the main pathways for cyber criminals is to lead someone to open and click on a link in an email which will unleash malware to penetrate the system, JSA said.
So, don’t open or click on unknown or suspicious emails. Even emails from people and customers or vendors that might seem familiar can be spoof emails or from someone who has obtained an email address only slightly different from a real email address.
Additionally, look for unfamiliar foreign domains, misspellings, and other anomalies.
5. Beware of social engineering, which is obtaining confidential information by manipulating and/or deceiving people.
Criminals can obtain information on company personnel, customers, ordering, shipping procedures, payment methods, and other information for a fraudulent transaction through impersonation, email correspondence, research on social media, or other means.
So, be careful of the information provided to the public by email, website, social media, or phone.
Also, confirm the identity of the person to whom you are talking. If the interaction includes a transaction, call the known customer on the telephone to confirm there hasn’t been fraudulent impersonation.
6. Avoid visiting questionable and risky sites.
7. Don’t download questionable apps from obscure or unknown companies.
8. Have a written cyber security policy that employees must read and sign.
9. Have regular staff meetings and periodic reviews of cyber protocols for the business.
The Latest

Their partnership combines Gemist’s customization technology with Saban Onyx’s U.S.-based manufacturing capabilities.

Respondents were concerned about the Middle East conflict and how it will impact their finances.

Our Piece of the Week, the “Butterfly” necklace, showcases a 7.02-carat oval diamond set between diamond, platinum, and 18-karat gold wings.

Gain access to the most exclusive and coveted antique pieces from trusted dealers during Las Vegas Jewelry Week.

Smith uses a comment he overheard in the grocery store to remind retailers that their job is to inspire buying behavior, not just sell.


“A Girl SMR at Claire’s” celebrates girlhood through the five senses with stacked jewelry, slime toys, scented accessories, and ASMR.

Believed to be one of three made in 1987, the Cartier London Crash was hot at the “Shapes of Cartier” sale at Sotheby’s Hong Kong.

Gain access to the most exclusive and coveted antique pieces from trusted dealers during Las Vegas Jewelry Week.

Sponsored by OROAREZZO International Jewelry Exhibition

Some retailers are taking a nuanced approach to marketing what can be a difficult holiday for many.

The Edge has announced its new CEO, as well as a new partnership with an investment firm focused on founder-led software businesses.

De Beers’ diamond production was up 17 percent in Q1, boosted by increased output at its mines in South Africa and Canada.

A signet ring belonging to the Western film star of Hollywood’s Golden Age will be up for auction at Elmwood’s next month.

Importers can submit claims now to receive money back for the IEEPA tariffs they’ve paid, with refunds expected to take up to 90 days.

The owners of Gregory Jewelers in Morganton, North Carolina, are heading into retirement.

The colored gemstone industry leader is heading into retirement after four years as the association’s CEO.

Susie Dewey joins the Natural Diamond Council as its new chief marketing officer.

The largest known fancy vivid blue-green diamond could fetch more than $12 million at its second auction appearance.

Emmanuel Raheb says jewelers need to start marketing early and make it easy for customers to pick a gift for mom.

In honor of the milestone, the Nebraska jeweler has debuted Leslie & Co., its new in-house jewelry brand.

The trade organization, which held its annual elections earlier this year, also added five new board members.

NRF’s annual survey found that 45 percent of consumers plan to purchase jewelry for a loved one this Mother’s Day.

The “Vault” charm, our Piece of the Week, expands on the memories that can be stored in a locket by connecting to your phone.

The open-to-the-public luxury jewelry and timepiece show, in its second year, is slated for July 23-26.

The jeweler’s Mother’s Day campaign highlights the women who work there—mothers, grandmothers, women who want to be mothers, and dog moms.

Sponsored by Jewelers Mutual

The proposed agreement follows the moissanite maker’s Chapter 11 bankruptcy protection filing last month.






















