Cyber Incident Victim: Watchfinder
Date:
Sep 2022
Location:
United Kingdom
Summary
A luxury watch marketplace experienced unauthorized access to an employee account, resulting in theft of customer data including email addresses, phone numbers, and purchase or interest records related to specific watches. While financial details, passwords, and physical addresses remained uncompromised, the exposed information creates risks for targeted phishing attempts and potential resale to other malicious actors. The company notified affected customers directly but did not issue any public security advisory through its official website or social media channels regarding the breach.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
In late September 2022, Watchfinder, a luxury pre-owned watch marketplace, experienced a data breach after unauthorized actors compromised an employee account and accessed customer records. The company notified affected individuals via email, confirming the exposure of personal information including email addresses, telephone numbers, and purchase history details related to specific watches customers had bought or expressed interest in acquiring. The breach did not involve financial data, passwords, or physical addresses according to the company's disclosure. The incident exposed sensitive consumer preferences that could indicate financial capacity and collecting habits, creating potential targeting opportunities for malicious actors. Watchfinder's notification occurred around September 30, 2022, though the initial intrusion date wasn't publicly specified beyond occurring "on or around" September 26.

The company's response included direct customer communications but omitted public announcements through its official website or social media channels like Twitter. No security advisory was published on corporate platforms despite the data's potential value for crafting targeted phishing campaigns or financial scams against high-net-worth individuals. The stolen watch preference lists created unique risks by revealing customer luxury purchasing behaviors beyond basic contact information. While Watchfinder confirmed containment of the compromised employee account, it provided no technical details about detection methods, attacker origins, or broader system impacts. The breach exclusively affected customer data with no indication of operational system disruption or additional compromised employee accounts beyond the initial entry point.
