Graff’s Ransomware Payment Not an Unusual Move, Expert Says
The high-end jeweler reportedly paid a $7.5 million ransom to a group of hackers and is suing its insurance company to cover the loss.

Ransomware is malware that uses encryption to hold a victim’s system or personal data hostage, basically, and demands payment to get them back.
Following the attack on Graff, Conti, the group that took credit for it, leaked data about the brand’s clients, such as their names and, potentially, their home addresses.
Graff counts many high-end clients and celebrities as customers, and the data breach included leaked data about the royal families in Saudi Arabia, the United Arab Emirates, and Qatar, prompting Conti to issue an apology to the families involved, an unusual move for the group.
Conti threatened to leak more of Graff’s data if the ransom wasn’t paid.
Though it tried to avoid paying, the high-end jeweler eventually offered $7.5 million, half the original ransom amount, and Conti accepted, according to Bloomberg, which broke the story. The jeweler paid in Bitcoin.
Graff is also suing its insurance company, The Travelers Companies Inc., in a London court for the losses, arguing that its policy should cover the ransom payment.
“The criminals threatened targeted publication of our customers’ private purchases. We were determined to take all possible steps to protect their interests and so negotiated a payment that successfully neutralized that threat,” a Graff spokesperson told National Jeweler.
“Regrettably, these commercial decisions are all too common these days. Insurers know this, which is why we are extremely frustrated and disappointed by Travelers’ attempt to avoid settlement of this insured risk. They have left us with no option but to bring these recovery proceedings at the High Court.”
The Travelers Companies did not respond to a request for comment by press time.
Shayne Caffrey, marketing manager and cybersecurity awareness training lead for LeeShanok Network Solutions, echoed what Graff Diamonds said it its statement—ransom payouts like this are fairly common today.
“Deciding whether to pay the ransom is a cost/benefit analysis. It can make a lot of sense to pay up when you can’t safely restore from a backup,” he said in an email to National Jeweler.
Once a business does decide to pay, it becomes a negotiation, going back and forth on price like in any deal until it becomes worth it for both sides.
“In this case, the initial $15 million demand may not have been worth it, but $7.5 million was,” Caffrey said. “Hackers would rather get something than nothing. This calculated approach means ransoms get paid more often than any of us would like.”
He also noted there’s rarely a guarantee that hackers will unencrypt the data even once the ransom is paid.
Caffey offered businesses two recommendations to reduce the chances of becoming a victim of cybercrime.
The first is to require every employee to undergo cybersecurity awareness training annually, with a particular focus on phishing prevention.
According to IBM, 95 percent of breaches result from human error, and the only way to fix that is through education, he noted.
But rather than using the common online training modules, Caffrey suggested bringing in a cybersecurity expert to deliver a live training, either in-person or virtually.
“In my experience, those trainings are much stickier.”
The second tip is to create a strong Backup and Disaster Recovery (BCDR) Strategy.
“Implementing these strategies can seem expensive on the surface, but they are often a fraction of the cost of paying a ransom, or even paying increased insurance premiums after a breach,” Caffrey said.
“Plus, it feels a lot better to restore your environment to a pre-ransomware instance than to reward the hackers by paying a ransom.”
More tips businesses can use to protect themselves from the Jewelers Security Alliance can be found in National Jeweler’s original story reporting on the Graff attack.
The Latest

Acquired by a tech investor, the historic brand will continue to focus on jewelry, accessories, and timepieces.

President Donald Trump issued an executive order extending the pause on higher tariffs to November as negotiations with China continue.

The “Thunderbird Slab” collection features a thunderbird motif as a symbol of power, protection, and boundless possibility.

As a leading global jewelry supplier, Rio Grande is rapidly expanding and developing new solutions to meet the needs of jewelers worldwide.

Columnists Jen Cullen Williams and Duvall O’Steen share tips on how to elevate your professional image.


Peter Damian Arguello, a jeweler in the Denver suburb of Wheat Ridge, was found dead inside his store in November 2023.

The retailer, owned by Berkshire Hathaway, is becoming part of the Berkshire Hathaway Jewelry Group with Helzberg.

The Seymour & Evelyn Holtzman Bench Scholarship from Jewelers of America returns for a second year.

The Continental Buying Group’s 2025 Tampa Experience Show is slated for Sept. 8-10.

Associate Editor Lauren McLemore recently attended a fabrics trade show where a trend forecaster shared her predictions for summer 2027.

The company raised its full-year sales guidance while noting it has not yet assessed the potential impact of the latest tariff news.

The organization has raised more than $1.3 million for charity since its inception.

The brand’s latest iteration of a bezel-set diamond bangle features clean lines and a timeless design for a new modern silhouette.

The first watch in the series commemorates his participation in the Civil Rights movement, marching from Selma to Montgomery in 1965.

The catalog contains a complete listing of all the loose gemstones in stock, as well as information about the properties of each stone.

An additional 25 percent tariff has been added to the previously announced 25 percent.

The jewelry and accessories retailer plans to close 18 stores as part of the proceedings.

Its Springfield, Massachusetts, store is set to close as owner Andrew Smith heads into retirement.

Designer Hiba Husayni looked to the whale’s melon shaped-head, blowhole, and fluke for her new chunky gold offerings.

She will present the 23rd edition of the trend forecasting book at Vicenzaoro on Sept. 7.

Omar Roy, 72, was arrested in connection with the murder of jeweler Dionisio Carlos Valladares.

The New Orleans-based brand’s “Beyond Katrina” jewels honor the communities affected by the storm.

Lilian Raji explains why joining an affiliate network is essential for brands seeking placements in U.S. consumer publications.

The organization has awarded a total of $42,000 through its scholarship programs this year.

The winner of the inaugural David Yurman Gem Awards Grant will be announced live at the 2026 Gem Awards gala.

As summer winds down, celebrate the sunny disposition of the month’s birthstones: peridot and spinel.

Moshe Haimoff, a social media personality and 47th Street retailer, was robbed of $559,000 worth of jewelry by men in construction outfits.