Pandora
Incident posture
Timeline
Summary
Pandora confirmed that a cyberattack gave unauthorized access to a third‑party platform, resulting in the copying of customer names and email addresses while passwords, credit card information and other confidential data remained secure. The company said the breach has been contained, security measures have been strengthened, and an internal investigation found no evidence of data leakage.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On August 5, 2025, Pandora sent an email at 09:15 Eastern Time confirming that it had experienced a cyberattack. The company described itself as the world’s largest jewelry brand and stated that the breach originated from access to a third‑party platform. According to the confirmation, the attackers were able to copy customer data that consisted only of names and email addresses. Pandora explicitly noted that no passwords, credit‑card information, or other confidential data were compromised in the incident. The email indicated that the attack had been identified and that the company was taking steps to address the situation.
Pandora said the attack had been contained and that security measures had been strengthened following the discovery. A spokesperson for the company emphasized that protecting customer privacy remained a priority and said extensive internal checks had found no evidence of further data leakage. The company also noted that it had notified relevant data protection authorities as part of its response process. The communication to customers included a note that they should remain alert to any suspicious emails or online activity linked to the breach. Pandora concluded by stating that it would continue to monitor its systems and work with relevant partners to prevent similar incidents.
Sources
Sources available to members: 1 source.