news.mlab.sh
Back to the feed
data-breach

77 Diamonds : 690 000 e-mails revendiqués en fuite

High
Summary

A shadowy hacker is claiming to possess a massive database of 77 Diamonds customer data, including nearly 700,000 email addresses, phone numbers, and physical addresses. The leaked information – encompassing customer orders, payment details, and internal notes – could be used to craft highly targeted and convincing phishing scams. This incident highlights the growing risk of data breaches targeting luxury goods retailers and the potential for sophisticated fraud operations.

A clandestine hacker is offering for sale a substantial database allegedly belonging to 77 Diamonds, a British jewelry company specializing in engagement rings, wedding jewelry, and certified diamonds. According to a report by ZATAZ, the hacker claims to have obtained approximately 690,000 unique email addresses, alongside 291,000 phone numbers and 409,000 real physical addresses. The leaked data includes customer orders, payment details, internal notes, and various authentication mechanisms.

77 Diamonds operates retail locations in London, Manchester, and Glasgow. The hacker’s offering indicates a wealth of customer information beyond standard contact details, including names, email addresses, phone numbers, passwords, account creation dates, Google identifiers, wedding dates, birthdates, languages, marketing consent, and customer IDs. Notably, the presence of a ‘password’ field doesn’t confirm that exploitable passwords are actually within the hacker’s possession, nor does it specify how they might be stored.

The leaked information also encompasses customer requests, appointments, addresses, orders, discounts, referral information, and sales interactions. Further details include budgets, delivery dates, ordered items, internal messages, IP addresses, and advertising identifiers.

ZATAZ has previously reported on black markets dealing in illicit goods like diamonds, gold, and platinum, often linked to cybercrime and money laundering. The potential value of this data to an attacker lies not just in volume, but in the contextual richness it provides for building highly credible and targeted fraud schemes.

Read the full article at ZATAZ