✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Luxury Goods/Jewelry
Breach intelligence, attack campaigns, and threat reports targeting the Luxury Goods/Jewelry sector.
Explore Other Sectors
Luxury Goods/Jewelry Threat Reports
Scattered Spider Hacker Traced via Windows Device ID
In May 2025, attackers infiltrated a luxury jewelry retailer by impersonating employees and convincing the IT help desk to reset passwords and multifactor authentication devices. They gained control over three accounts, including two IT administrators, installed tunneling tools, and exfiltrated at least 77 gigabytes of data. Although the attackers attempted to deploy ransomware, the retailer's security team thwarted the effort. The attackers demanded an $8 million ransom, which the company refused to pay, resulting in approximately $2 million in losses due to disruption and remediation efforts. The incident underscores the critical importance of robust identity verification processes for IT support functions. It also highlights the necessity of implementing phishing-resistant multifactor authentication methods and continuous monitoring to detect and prevent unauthorized access attempts.
2 weeks ago
Kill Chain
Scattered Spider Member Peter Stokes Extradited to US in 2026
In July 2026, Peter Stokes, a 19-year-old dual U.S.-Estonian citizen and alleged member of the cybercriminal group Scattered Spider, was extradited to the United States following his arrest in Finland. Stokes is accused of participating in multiple data theft and extortion attempts, including attacks on a luxury jewelry retailer in May 2025 and a U.S.-based insurance company in June 2025. Scattered Spider, active since 2022, has infiltrated over 100 businesses and extorted more than $100 million globally. ([cyberscoop.com](https://cyberscoop.com/scattered-spider-peter-stokes-cybercrime-extradition/?utm_source=openai)) This incident underscores the persistent threat posed by cybercriminal groups employing sophisticated social engineering tactics to infiltrate organizations. The arrest highlights the importance of robust cybersecurity measures and international cooperation in combating cybercrime.
2 weeks ago
Kill Chain
Seiko USA Website Defaced: Hackers Claim Customer Data Theft
In April 2026, Seiko USA's website was defaced by attackers who claimed to have breached the company's Shopify backend, exfiltrating sensitive customer data including names, email addresses, phone numbers, order histories, and shipping information. The attackers demanded a ransom, threatening to publicly release the stolen data if their demands were not met. Seiko USA has not publicly confirmed the breach, and the defaced content has since been removed from the website. This incident underscores the growing trend of cybercriminals targeting e-commerce platforms to access customer data, highlighting the critical need for robust security measures and prompt incident response strategies to protect sensitive information and maintain customer trust.
3 months ago
Kill Chain
Sotheby’s 2025 Data Breach: Employee Financial Data Compromised
In July 2025, Sotheby's, the renowned international auction house, identified a significant cybersecurity breach in which an unknown threat actor exfiltrated sensitive employee information, including full names, Social Security numbers, and financial account details. The breach was discovered on July 24, 2025, and an internal investigation with data protection experts and law enforcement extended over two months to confirm the nature and scope of compromised data. Sotheby’s responded by notifying impacted employees and offering a year of free identity protection and credit monitoring services. No ransomware group claimed responsibility, and the number of affected individuals remains undisclosed. This incident underscores ongoing risks facing financial and high-value service sectors, especially from sophisticated attacks targeting personnel data for monetization and fraud. Organizations with sensitive employee or client financial data must act promptly as regulatory scrutiny tightens and attacks on high-net-worth entities continue to escalate.
6 months ago
Kill Chain
Sotheby's 2025 Data Breach: When Sensitive Customer Information Goes Public
In July 2025, Sotheby's, a leading global auction house, suffered a significant data breach in which threat actors exfiltrated sensitive customer data. Discovered on July 24, the breach resulted in the exposure of customers' full names, Social Security numbers, and financial account information. An internal investigation spanned two months, determining the scale and nature of the data affected and the impacted individuals, which included Maine and Rhode Island residents. While the number of victims remains undisclosed, Sotheby's began notifying those affected and offered complimentary identity protection and credit monitoring. No ransomware group has publicly claimed responsibility, and the attack’s vector remains unknown, but similar institutions have faced ransomware- and data-theft-related intrusions in recent years. This incident underscores the rising frequency and impact of data breaches targeting well-known, high-value companies, particularly those handling sensitive customer and financial information. It highlights pressing concerns around regulatory compliance, the need for comprehensive incident detection and response, and growing regulatory scrutiny of data protection practices in sectors beyond traditional financial services.
6 months ago
Kill Chain
Harrods Suffers Major Supply Chain Breach: 430,000 Customer Records Exposed in 2025
In September 2025, UK luxury retailer Harrods disclosed a major cybersecurity incident after attackers exploited a vulnerability in a third-party supplier, leading to the exposure of 430,000 e-commerce customer records. The breach, unrelated to earlier attacks by Scattered Spider, leveraged a supply chain vector similar to the widespread Salesloft OAuth attack, allowing data exfiltration from connected Salesforce environments. Compromised data included names, contact information, and internal marketing labels, but excluded financial data and passwords. Harrods responded by promptly notifying affected customers and authorities, while refusing to engage with extortion attempts by the threat actor. This incident illustrates the growing risk of supply chain compromise in the retail and e-commerce sector, where attackers increasingly exploit third-party platforms for large-scale data theft. As regulatory scrutiny intensifies and similar attacks proliferate, organizations must reevaluate supply chain security controls and customer notification protocols.
6 months ago
Kill Chain
2025 Retail Salesforce Data Heist: Extortion Attack Exposes Cloud Security Gaps
In mid-2025, a sophisticated data extortion campaign targeted high-end retail organizations leveraging Salesforce environments. Threat actors—identified as UNC6040 (responsible for access and reconnaissance) and Bling Libra (aka ShinyHunters, handling extortion)—gained initial access through voice-based phishing (vishing) techniques. After establishing a foothold, they conducted in-depth reconnaissance to collect sensitive customer data, including names, birthdates, contact details, and account metadata, which was then exfiltrated. The attackers threatened public disclosure unless the victim organizations paid a ransom, all while leaving minimal forensic traces due to a lack of malware deployment and custom tools. This incident highlights the increasing sophistication of financially motivated cybercrime operations and an industry-wide shift towards data theft extortion without ransomware. There is an urgent need for retail and cloud-reliant enterprises to reassess their security controls, as social engineering vectors bypass traditional perimeter defenses and regulatory scrutiny around cloud data protections intensifies.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports