In the Wake of the Cyberattack on Stuller, 5 Tips on Cybersecurity

CrimeDec 09, 2020

In the Wake of the Cyberattack on Stuller, 5 Tips on Cybersecurity

From password security to tracking-number safety, here are five cybersecurity tips to keep in mind.

The Jewelers’ Security Alliance shared tips on how to safely connect with customers online.

New York—Stuller was hit by a cyberattack over Thanksgiving weekend that delayed shipments, shut down the phone lines, and created other operational issues amid the holiday rush.

It took a few days for the massive manufacturer and supplier to get same-day shipping services on in-stock items and the phone lines back up and running.

While Stuller said there was no indication that sensitive business information was compromised—noting that customer credit cards on file are tokenized, encrypted, and not housed at Stuller—the stressful disruption came at the most critical time of the year for the supplier, underscoring the need for businesses today to invest in cybersecurity.

Stuller did not provide additional details on the specifics of the cyberattack.

In a COVID-19 world, and even before then, the ability to connect with customers online is crucial, whether one is running a consumer-facing retail store or a business-to-business operation.

Here are five expert tips on how to navigate the online world safely.

Ensure employees are adequately protected as they work from home.

Law enforcement officials have seen an uptick in fraud and hacking now that more people are working from home on computers or smartphones less secure than those in their office, the Jewelers’ Security Alliance said in a recent memo.

Be sure all employees’ devices have updated protections in place, including firewall, malware, and spam protection.

Stop using the same password for everything.

JSA advises having “strong, unique” passwords.

When the password for everything is the same, it may be easy to remember, but it’s also easy for hackers to gain access to several accounts in one swoop.

Users may also want to set up two-factor or multi-factor authentication.

“If a cybercriminal were to gain access to your log-in credentials, they wouldn’t be able to compromise your account if they didn’t have access to a passcode that would be sent to your phone,” explained Ryan Ruddock, senior research assistant at JSA, during an October webinar on online scams.

If you’re unsure about an email, just don’t open it.

Be wary of email phishing scams, which are attempts to trick users into giving criminals access to personal information.

“The intention behind phishing is to acquire personally identifiable information. So that’s going to include credit card information, social security numbers, account log-in credentials, and, in some cases, intellectual property,” said Ruddock.

It’s the most common type of cybercrime, said Ruddock, noting that it doesn’t target specific individuals.

Criminals will send a mass email in the

hopes that some percentage will respond.

Misspellings and poor grammar are red flags to look for in phishing emails, he said, but also be wary of any email sent with a sense of urgency, pressuring users to act now, think later.

If an email doesn’t look trustworthy, don’t open it or click on any links. Delete it.

If a link in what is believed to be a phishing email is clicked, Ruddock recommended disconnecting from the WiFi, which could prevent malware from being installed on your computer, running an anti-virus scan, and changing passwords.

Also, be on the lookout for email spoofing, which involves an email sent from an address that’s almost, but not quite, identical to a genuine email address for a contact.

An email might look like it’s coming from longtime vendor, such as, but upon closer inspection, it may actually read

If anything about the email seems off, it’s best to contact the vendor or customer by phone and be sure the request is genuine, JSA said.

Be careful with tracking numbers.

For any questions about a transaction, it’s best to reach out to the customer by phone via the number given at the time of purchase.

“You do not want to use the number given to you by the caller,” advised Ruddock.

JSA does not advise giving out the tracking number on a shipment. If a tracking number of a package is given to someone other than the customer, it may be possible for that person to redirect the merchandise.

JSA has also seen cases where a caller, pretending to be from a retail store, contacts a supplier and requests that a high-end item be sent to the store. The caller later diverts the shipment to a different address.

Set a limit on the number of times an address can be changed on a shipment, said Ruddock, and be clear with the shipper about how change of address requests should be handled.

Some companies, he said, have specified to their shipping company that if there are any attempts to change the address, the package should instead be returned to the company.

Make sure employees know the company’s cybersecurity policy.

Every company should have a written cybersecurity policy that is read and signed by employees, said JSA.

Be sure to regularly review the cyber-protocols with employees so everyone is on the same page.

Select cyber security firms also offer tests that allow employers to determine their employees’ ability to avoid phishing attacks and other scams.

Provide additional training to those employees who need it, advised Ruddock.

For more information about cybersecurity, visit the JSA website.
Lenore Fedowis the associate editor, news at National Jeweler, covering the retail beat and the business side of jewelry.

The Latest

WatchesApr 22, 2021
Check Out All Patek Philippe’s 2021 Newness

The watchmaker showed what’s new in Nautilus, revamped Calatrava models, and a brand-new perpetual calendar.

Policies & IssuesApr 22, 2021
US Government Sanctions Burmese State-Owned Pearl Co.

Myanmar Pearl Enterprise handles oyster fishing and breeding, as well as the culturing, harvesting, and selling of pearls.

MajorsApr 22, 2021
Tiffany Signs K-Pop Star Rosé as New Ambassador

Blackpink member Rosé will be the face of the 2021 Tiffany HardWear campaign.

Brought to you by
A New Golden Age

Gold has had its share of ups and downs over the last 5 decades. Here’s why the metal is having another big comeback.

Events & AwardsApr 22, 2021
BIJC, Ben Bridge Introduce a New Scholarship

Named for the late Lonia Tate, the scholarship is for the Graduate Gemology program at GIA, with an internship at the jeweler to follow.

Weekly QuizApr 16, 2021
This Week's Quiz
Test your knowledge of jewelry news from the week of April 12-16, 2021.
Take the Quiz
Events & AwardsApr 22, 2021
IEG Pushes Oroarezzo Italian Jewelry Trade Show to 2022

It was originally slated for June 12-15 at the Expo Centre in Arezzo, Italy.

SourcingApr 21, 2021
Why Inclusivity Is Important in Diamond Traceability

As the importance of mine-to-market grows, some worry about its feasibility for all the diamond industry’s players.

Brought to you by
4 Reasons You Need This Program for Mother’s Day

Learn how to increase customer loyalty and revenue by making JM™ Care Plan a cornerstone of your business plan.

CollectionsApr 21, 2021
Alrosa’s ‘Luminous’ Collection Leans Into Fluorescence

The diamond miner and seller is marketing the stones for their glow.