Pandora
Incident posture
Timeline
Summary
Pandora confirmed a cyberattack in which attackers accessed a third‑party platform and copied names and email addresses, while passwords, credit card details and other confidential data remained secure. The company said the breach has been contained, that extensive checks found no evidence of further data leakage, and that security measures have been strengthened.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On August 5, 2025, Pandora issued a confirmation via email at 09:15 Eastern Time that it had experienced a cyberattack. The company described itself as the world’s largest jewelry brand and stated that the breach originated from unauthorized access to a third‑party platform. According to the notice, the attackers were able to copy only common personal data such as names and email addresses. Pandora explicitly said that no passwords, credit‑card information, or other confidential data were compromised in the incident. The email also noted that the attack had been contained and that additional security measures had been put in place. The Forbes article reporting the confirmation was published on August 5, 2025.
Pandora’s spokesperson emphasized that protecting customer privacy remained a priority and said that extensive internal checks had found no evidence of any data leakage beyond the copied names and email addresses. The company advised recipients to remain alert for possible phishing attempts that might use the exposed information. Pandora stated that it would continue to monitor its systems and work with relevant partners to prevent similar incidents. The notice concluded by reminding customers to be vigilant against suspicious emails or online activities linked to the breach.
Sources
Sources available to members: 1 source.