Graff Gets Hit by Ransomware Attack
The data breach included some personal details of high-end clients.

Ransomware is malware that uses encryption to hold a victim’s system or personal files and demands payment to get them back.
For most people involved in the Graff data breach, it included details like their name and potentially their home address—which can be retrieved in the public domain from other sources– rather than any other confidential details that would put them at risk of identity theft.
A Graff spokesperson said the brand informed “the small group of individuals whose personal data was compromised to such an extent” and advised them on the appropriate steps to take.
The brand’s security systems alerted it to the activity, allowing it to react quickly and shut down its network.
Graff said it has been working with the U.K.’s Information Commissioner’s Office and relevant law enforcement on the incident.
“Thanks to our robust back-up facilities we were able to rebuild and restart our systems within days - crucially with no irretrievable loss of data,” the spokesperson said.
“Sadly, it appears that notable brands, corporations and even government departments are deliberately targeted by unscrupulous operators to extort money, cause disruption or simply embarrassment. Cybercrime continues to rise in scale and complexity. It is a threat to every business. Maintaining the highest level of security against these threats has always been a top priority for us. We are continually strengthening our systems to counter these threats as they evolve.”
The group known as Conti is said to be behind the attack, the U.K.’s The Times reported, leaking the details of the brand’s high-end clientele to the dark web.
In a September press release, the Cybersecurity and Infrastructure Security Agency said it and the Federal Bureau of Investigation had seen an increase in the use of Conti ransomware in more than 400 attacks on U.S. and international organizations.
Earlier this year, the FBI said it had identified at least 16 Conti ransomware attacks that targeted healthcare and first responder networks in the U.S.
While the hacks that tend to make headlines are the bigger ones, small businesses should also protect themselves against such crimes.
The Jewelers’ Security Alliance recommends the following actions to prevent cybercrime.
1. Have proper firewalls, anti-virus, and anti-malware for all systems, and keep them up to date.
2. Don’t let employees use company internet-connected devices at work for personal use or download software without permission. Additionally, don’t let them introduce personal memory sticks into a company system.
3. Have strong, unique passwords.
4. Beware of phishing. One of the main pathways for cyber criminals is to lead someone to open and click on a link in an email which will unleash malware to penetrate the system, JSA said.
So, don’t open or click on unknown or suspicious emails. Even emails from people and customers or vendors that might seem familiar can be spoof emails or from someone who has obtained an email address only slightly different from a real email address.
Additionally, look for unfamiliar foreign domains, misspellings, and other anomalies.
5. Beware of social engineering, which is obtaining confidential information by manipulating and/or deceiving people.
Criminals can obtain information on company personnel, customers, ordering, shipping procedures, payment methods, and other information for a fraudulent transaction through impersonation, email correspondence, research on social media, or other means.
So, be careful of the information provided to the public by email, website, social media, or phone.
Also, confirm the identity of the person to whom you are talking. If the interaction includes a transaction, call the known customer on the telephone to confirm there hasn’t been fraudulent impersonation.
6. Avoid visiting questionable and risky sites.
7. Don’t download questionable apps from obscure or unknown companies.
8. Have a written cyber security policy that employees must read and sign.
9. Have regular staff meetings and periodic reviews of cyber protocols for the business.
The Latest

The 111-year-old store will close following a dispute among Saks Global, a landlord, and the City of Dallas over a small piece of land.

The upcoming “Area_51” watch sale is a collaboration with heist-out, featuring vintage and modern timepieces with futuristic designs.

The trade organization, which will mark 120 years of service next year, has a refined focus and a new mission statement.

Emergencies can happen anytime, anywhere , and Jewelers of America has what you need to be prepared for it all.

The application period is now open for established and emerging jewelers and metalsmiths to apply to the month-long residency program.


The March birthstone pairs perfectly with hues of Mocha Mousse, Pantone’s Color of the Year for 2025.

Emmanuel Raheb shares strategies to prepare for, publicize, and engage the audience during events on platforms like TikTok and Zoom.

The jewelry industry faces challenges from lab-grown diamonds. A diamond ETF can restore natural diamonds' value and drive investor demand.

From Doja Cat to Mikey Madison and Selena Gomez, many of this year’s Academy Awards attendees donned drop necklaces.

Originally slated to take effect in April, official U.S. Customs and Border Protection documents now show the implementation date as “TBD.”

The recent jump in the prices of household staples, like eggs, and the potential impact of tariffs worried consumers.

The application period for the program is now open for aspiring gemologists around the world.

The work of Indigenous designer Joe Big Mountain, these earrings are similar to the pair Lily Gladstone just wore to the SAG Awards.

A metal detectorist uncovered the ring created in memory of Sir Richard Rainsford, who presided over some of England’s last witch trials.

Fine jewelry consultant and publicist Francesca Simons joins Amanda Gizzi and Natalie Francisco to discuss the trends set to rise this year.

Harlow’s partner, NBA player Kyle Kuzma, worked with Vobara to design the ring, which features oval and pear-shaped diamonds.

The Danish jeweler released the next chapter of its “Be Love” campaign, which celebrates love in all its forms.

The 13 lots on offer were comprised of material that previously went unsold at the miner’s November auction.

The learning workshop and the convention are both scheduled to take place April 26 and 27 in Montgomery, Alabama.

The EU, like the U.S., also now will require diamond importers to provide information about where exactly the diamonds were mined.

The formal signing of the agreement comes nearly two years after De Beers and Botswana initially announced they had reached a new deal.

The charity will celebrate Pandora CEO Alexander Lacik and Brilliant Earth CEO Beth Gerstein at its annual event in Las Vegas.

Retailers need to have the right merchandise, marketing, and people in place to stay on top in a sea of uncertainty, Peter Smith writes.

Senior Editor Lenore Fedow traveled to Smyth Jewelers in Maryland to see the first of 15 revamped in-store boutiques Tacori is rolling out.

The parent company of HSN and QVC is undergoing a restructuring.

The company’s newest brand ambassador Eiza González will also be featured in the ads for the women’s campaign.

Declining supply and growing demand persist in the colored gemstone market, presenters from Gemworld said at AGTA GemFair Tucson.