CSIDB logo
Incident

Pandora

Incident posture

Attack window
Nov 2025
Location
Denmark
Status
Resolved
CIA posture
Available to members
Updated
2026-08-17 16:54

Linked entities

Victim
Pandora
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Undetermined
Disclosed
Aug 2025
Resolved
Aug 2025

Summary

Pandora confirmed that a cyberattack gave unauthorized access to a third‑party platform, resulting in the copying of customer names and email addresses while passwords, credit card information and other confidential data remained secure. The company said the breach has been contained, security measures have been strengthened, and an internal investigation found no evidence of data leakage.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On August 5, 2025, Pandora sent an email at 09:15 Eastern Time confirming that it had experienced a cyberattack. The company described itself as the world’s largest jewelry brand and stated that the breach originated from access to a third‑party platform. According to the confirmation, the attackers were able to copy customer data that consisted only of names and email addresses. Pandora explicitly noted that no passwords, credit‑card information, or other confidential data were compromised in the incident. The email indicated that the attack had been identified and that the company was taking steps to address the situation.

Pandora said the attack had been contained and that security measures had been strengthened following the discovery. A spokesperson for the company emphasized that protecting customer privacy remained a priority and said extensive internal checks had found no evidence of further data leakage. The company also noted that it had notified relevant data protection authorities as part of its response process. The communication to customers included a note that they should remain alert to any suspicious emails or online activity linked to the breach. Pandora concluded by stating that it would continue to monitor its systems and work with relevant partners to prevent similar incidents.

Sources

Sources available to members: 1 source.

CSIDB