Technology

Graff’s Ransomware Payment Not an Unusual Move, Expert Says

TechnologyJul 12, 2022

Graff’s Ransomware Payment Not an Unusual Move, Expert Says

The high-end jeweler reportedly paid a $7.5 million ransom to a group of hackers and is suing its insurance company to cover the loss.

2022_Cyber-security.jpg
London—Graff Diamonds reportedly paid a $7.5 million ransom in Bitcoin to the hackers responsible for a ransomware attack on its systems last fall, a decision that is not unusual for large companies today, one expert says.

Ransomware is malware that uses encryption to hold a victim’s system or personal data hostage, basically, and demands payment to get them back.

Following the attack on Graff, Conti, the group that took credit for it, leaked data about the brand’s clients, such as their names and, potentially, their home addresses.

Graff counts many high-end clients and celebrities as customers, and the data breach included leaked data about the royal families in Saudi Arabia, the United Arab Emirates, and Qatar, prompting Conti to issue an apology to the families involved, an unusual move for the group.

Conti threatened to leak more of Graff’s data if the ransom wasn’t paid.

Though it tried to avoid paying, the high-end jeweler eventually offered $7.5 million, half the original ransom amount, and Conti accepted, according to Bloomberg, which broke the story. The jeweler paid in Bitcoin. 

Graff is also suing its insurance company, The Travelers Companies Inc., in a London court for the losses, arguing that its policy should cover the ransom payment. 

“The criminals threatened targeted publication of our customers’ private purchases. We were determined to take all possible steps to protect their interests and so negotiated a payment that successfully neutralized that threat,” a Graff spokesperson told National Jeweler. 

“Regrettably, these commercial decisions are all too common these days. Insurers know this, which is why we are extremely frustrated and disappointed by Travelers’ attempt to avoid settlement of this insured risk. They have left us with no option but to bring these recovery proceedings at the High Court.”

The Travelers Companies did not respond to a request for comment by press time.

 Related stories will be right here … 

Shayne Caffrey, marketing manager and cybersecurity awareness training lead for LeeShanok Network Solutions, echoed what Graff Diamonds said it its statement—ransom payouts like this are fairly common today.

“Deciding whether to pay the ransom is a cost/benefit analysis. It can make a lot of sense to pay up when you can’t safely restore from a backup,” he said in an email to National Jeweler.

Once a business does decide to pay, it becomes a negotiation, going back and forth on price like in any deal until it becomes worth it for both sides. 

“In this case, the initial $15 million demand may not have been worth it, but $7.5 million was,” Caffrey said. “Hackers would rather get something than nothing. This calculated approach means ransoms get paid more often than any of us would like.”

He also noted there’s rarely a guarantee that hackers will unencrypt the data even once the ransom is paid.

Caffey offered businesses two recommendations to reduce the chances of becoming a victim of cybercrime.

The first is to require every employee to undergo cybersecurity awareness training annually, with a particular focus on phishing prevention.

According to IBM, 95 percent of breaches result from human error, and the only way to fix that is through education, he noted.

But rather than using the common online training modules, Caffrey suggested bringing in a cybersecurity expert to deliver a live training, either in-person or virtually.

“In my experience, those trainings are much stickier.”

The second tip is to create a strong Backup and Disaster Recovery (BCDR) Strategy.

“Implementing these strategies can seem expensive on the surface, but they are often a fraction of the cost of paying a ransom, or even paying increased insurance premiums after a breach,” Caffrey said.

“Plus, it feels a lot better to restore your environment to a pre-ransomware instance than to reward the hackers by paying a ransom.”

More tips businesses can use to protect themselves from the Jewelers Security Alliance can be found in National Jeweler’s original story reporting on the Graff attack.

The Latest

National Jeweler columnist Peter Smith
ColumnistsJan 21, 2025
Peter Smith: Sales Training’s Dirty Little Secret

Peter Smith pulls back the curtain on the often misinterpreted, and sometimes maligned, world of sales training.

Lord Jewelry brown and white diamond ring
TrendsJan 21, 2025
Amanda’s Style File: Decadent Mocha Mousse

Pantone’s 2025 Color of the Year takes the form of jewelry through gemstones and enamel that look just as delicious as mocha mousse.

Charms from designer Jenna Blake
Policies & IssuesJan 21, 2025
These Designers and Retailers Are Raising Money for LA Wildfire Relief

From raffles to auctions to donations, the industry is working to aid charities in Los Angeles amid the raging wildfires.

Resolutions - 2025.jpg
Brought to you by
3 New Year’s Resolutions for Jewelry Lovers

The new year feels like a clean slate, inspiring reflection, hope, and the motivation to become better versions of ourselves.

Diamonds Do Good
SourcingJan 21, 2025
Diamonds Do Good Adds 2 Board Members

Julia Hackman Chafé and Monica Elias have joined the organization’s board of directors.

Weekly QuizJan 16, 2025
This Week’s Quiz
Test your jewelry news knowledge by answering these questions.
Take the Quiz
Bucellati necklaces
FinancialsJan 17, 2025
Richemont’s Jewelry Sales Rise 14% in Holiday Quarter

The company, which owns Cartier and Van Cleef & Arpels, had a record Q3, with sales topping $6 billion.

Picchiotti Classic Blue and Green Necklace
CollectionsJan 17, 2025
Piece of the Week: Picchiotti’s Transformable ‘Classic Blue and Green’ Necklace

The necklace features a sapphire drop weighing more than 9 carats that detaches to transform into a ring.

ride_or_die_1872x1052.png
Brought to you by
A Diamond Is Forever Celebrates "Forever Present" Holiday Campaign

A Diamond is Forever hosted a holiday celebration in honor of their new marketing campaign, ‘Forever Present.’

Jameel Mohammed
MajorsJan 17, 2025
Tiffany & Co., CFDA Name First Winner of Jewelry Designer Award

Jameel Mohammed, founder of Afrofuturist brand Khiry, will receive a cash prize and a one-year paid fellowship with Tiffany & Co.

Gold jewelry boxes with Lux Bond & Green logo
IndependentsJan 16, 2025
Lux Bond & Green to Open Sixth Location

The 127-year-old jeweler is planning to open a new store in Mystic, Connecticut.

Timex National Park Collection
WatchesJan 16, 2025
Timex Launches Collection of National Park Watches

The watches’ dials feature artwork celebrating the vibrant energy and unique landscapes of six of America’s national parks.

Elizabeth Taylor diamond line bracelet
AuctionsJan 16, 2025
Elizabeth Taylor’s Diamond Line Bracelet Going up for Auction

Offered by U.K. auction house Woolley & Wallis, the yellow diamond bracelet was a gift from Taylor’s good friend Michael Jackson.

JCK open registration graphic
Events & AwardsJan 16, 2025
JCK Las Vegas 2025 Open for Registration

The jewelry trade show returns to The Venetian Expo and The Venetian Resort in Las Vegas from June 6 to 9.

Iris Apfel
EditorsJan 15, 2025
The Jewelry I’d Bid On in Christie’s Iris Apfel Auction

Associate Editor Natalie Francisco highlights her favorite fashion jewelry pieces from the upcoming “Unapologetically Iris” auction.

Macy’s Herald Square New York City store
MajorsJan 15, 2025
Macy’s to Close 66 Stores as Part of Turnaround Strategy

The closures are part of the retailer’s plan to close 150 locations over a three-year period.

Jewelers Vigilance Committee Americans with Disabilities Act guide cover
Policies & IssuesJan 15, 2025
JVC Debuts Guide to Americans with Disabilities Act Compliance

The online guide is available for free and written with the jewelry industry in mind.

Jose Hess Design Award Trophy
Events & AwardsJan 15, 2025
Jose Hess Design Awards Open for Submissions

The awards honor the late Jose Hess, a founding member of AJDC and an award-winning jewelry designer.

Susan Jacques
GradingJan 14, 2025
GIA CEO, President Susan Jacques to Retire at the End of 2025

The grading lab said the search for her successor is underway.

Jewelry designer and National Jeweler guest columnist Jules Kim
ColumnistsJan 14, 2025
Jules Kim: Building Bridges Between Creators and Industry

In this special op-ed, designer Jules Kim calls on big brands to collaborate with independent creators instead of copying their designs.

Henry A. Hänni
GradingJan 14, 2025
Former SSEF Director Henry A. Hänni Dies

A pioneering figure in gemology, he is remembered for his spirit of generosity, curiosity, and joy.

Woman wearing rings on both hands
FinancialsJan 14, 2025
Signet Jewelers Lowers Q4 Guidance After Holiday Sales Fall Short

The peak selling days leading up to Christmas did not meet the jewelry retailer’s expectations.

Edouard Schneider
MajorsJan 14, 2025
Edouard Schneider Joins Messika as Chief Brand Officer

Schneider brings over 20 years of luxury and fashion industry experience to his role as a key member of the brand’s global leadership team.

Gemfields emeralds
SourcingJan 13, 2025
Zambia Reinstates 15% Export Duty on Precious Gemstones, Shocking Gemfields

Gemfields said the Zambian government revoked the 2019 suspension of the tax with no warning.

Brandee Dallow
Policies & IssuesJan 13, 2025
Brandee Dallow Elected President of Ethical Metalsmiths

The executive brings more than two decades of industry experience to the role.

Camille Zarsky and curated necklaces
IndependentsJan 13, 2025
The Seven Pops Up in Palm Beach

The New York City-based retailer is bringing its curation of jewels to a pop-up shop at Love Binetti in Palm Beach, Florida.

Jewelers Relief Fund logo
Policies & IssuesJan 10, 2025
Jewelers Relief Fund Reopened to Aid Victims of LA Fires

Created by JA and DCA, the fund is collecting money for jewelry businesses damaged by the wildfires in Los Angeles County.

Elsa Jin Mozi Brooch
TrendsJan 10, 2025
Piece of the Week: Elsa Jin’s ‘Mozi’ Brooch

Adrien Brody received his first Golden Globe while wearing the “Mozi” brooch, which depicts a spill of traditional Chinese calligraphy ink.

×

This site uses cookies to give you the best online experience. By continuing to use & browse this site, we assume you agree to our Privacy Policy