77 Diamonds Investigates Alleged Hack of Customer Data
September 06, 26
(IDEX Online) - London-based jeweler 77 Diamonds is investigating an alleged cyberattack after a threat actor claimed to have obtained a database containing hundreds of thousands of customer records.
The Times reported on September 5 that the Metropolitan Police cybercrime unit was investigating a possible attack involving data on more than 409,000 customers. The newspaper said the hackers claimed to have obtained home addresses, names, email addresses and information about purchases.
A separate threat-intelligence post by Dark Web Intelligence said an underground forum listing offered what the threat actor claimed was a database containing about 700,000 records. It said the alleged dataset included about 690,000 unique email addresses, 461,000 records containing last names, 291,000 phone numbers and 409,000 physical street addresses.
The figures relate to different categories of information and should not be treated as a count of individual customers. The alleged 700,000 records could include multiple records relating to the same customer, while the 409,000 figure refers specifically to physical addresses.
The alleged database was also said to contain first and last names, gender, birth dates, customer identifiers, account creation information, newsletter and marketing preferences and other account metadata. Dark Web Intelligence said a sample of the alleged database was included in the underground forum post. The claims have not been independently verified.
Tobias Kormind, managing director of 77 Diamonds, said after a review of sample data it could confirm that it contained no customer home addresses.
"We are aware that a third party is claiming online to have accessed customer information held by 77 Diamonds, but the wider claims remain under investigation and have not been verified," he said.
"Following a detailed investigation with external cyber security specialists, we have not yet been able to establish conclusively whether any customer information was accessed or extracted from our systems. That investigation remains ongoing. We have not, to date, received any reports from customers that they have been targeted as a result of the matters we are investigating."
in an email to customers he said: "We are investigating a possible unauthorised access to, and misuse of, a customer database and have taken immediate steps to secure our systems."
He said the company had engaged cybersecurity advisers and notified the UK's Information Commissioner's Office.
Kormind also said: "At this stage, we cannot confirm whether your personal information specifically was accessed." The company said it was contacting customers so they could take appropriate precautions while the investigation continued.
77 Diamonds does not hold customers' banking details. Kormind told The Times that no customers had reported being targeted.
The company's cybersecurity team had examined a sample of the alleged material that did not include customers' home addresses. The investigation is continuing.
The alleged exposure could be particularly sensitive for a jeweler because the data may identify people who have purchased high-value engagement rings, wedding jewelry or diamonds.
If authentic, the combination of email addresses, phone numbers, physical addresses and purchase information could facilitate targeted phishing, impersonation and social-engineering attacks.
77 Diamonds was founded in 2005 by Kormind and Antwerp diamond broker Vadim Weinig. The company was built as an online-first jeweler, sourcing diamonds directly from manufacturers and offering custom-made jewelry, with its own craftsmanship and design operation.
It opened its showroom and workshop in Hanover Square in Mayfair, a central London district known for luxury retail, galleries and high-end businesses, in 2013. The company now has showrooms in several European cities and says its online selection includes as many as 1.8 million independently graded diamonds.
The latest UK accounts show 77 Diamonds Limited had turnover of £32.9 million in 2024, with 115 average employees. The Times reported that the wider business employed about 150 people and had 14 branches in the UK, Europe and the Middle East.
The incident follows several recent cyberattacks involving major jewelry and luxury businesses.
In June 2025, Cartier confirmed that an unauthorized party had accessed its systems and obtained limited customer information, including names, email addresses and countries of residence. The company said passwords, credit-card details and banking information were not compromised.
Christie's suffered a cyberattack in May 2024 that forced it to take its website offline during its major New York auction season. The auction house later confirmed that an unauthorized third party had accessed parts of its network and that a limited amount of personal data relating to some clients had been taken.
It said there was no evidence that financial or transactional data had been compromised. The ransomware group RansomHub had claimed to have data on at least 500,000 clients, but that figure was not confirmed by Christie's.
In September 2025, German jewelry and watch retailer CHRIST said a targeted cyberattack had allowed attackers to access personal data and extract some of it.
Potentially affected information included customer numbers, names, contact details and purchase history, while passwords, credit-card details and other payment data were not affected. The company said it had brought in external cyber-incident and forensic specialists and notified the relevant authorities.
The Metropolitan Police investigation and the company's own inquiry remain ongoing, and the scale and authenticity of the alleged 77 Diamonds data breach have not been established.
Picture shows: Tobias Kormind, director of 77 Diamonds.