A threat actor claims to have breached UK jeweller 77 Diamonds and is offering a database allegedly containing information tied to hundreds of thousands of customers, including email addresses, phone numbers and residential addresses.
The claim was published on Aug. 26 and describes a dataset containing approximately 690,000 unique email addresses. The threat actor further claims that about 461,000 records contain last names, 291,000 include phone numbers and approximately 409,000 contain street addresses.
Samples accompanying the post appear to contain recently created customer records dated as late as Aug. 23, potentially indicating that at least part of the dataset is recent. BreachNews has not independently verified the complete database or established how the information was allegedly obtained.
Customer database appears to extend beyond contact details
The exposed database structure allegedly includes names, email addresses, telephone numbers, account creation dates, birth dates, wedding dates, newsletter preferences and other customer account information.
Additional tables listed by the threat actor suggest the database may contain considerably more than the main customer table. The purported dump includes tables associated with customer addresses, enquiries, appointments, orders, payments, referrals, marketing records and interactions with 77 Diamonds staff.
Some database structures also reference payment-related information, including card brands, expiration dates, the last 4 digits of payment cards and payment processing results. The listing does not establish how many customers, if any, have payment-related information in the allegedly stolen dataset, and BreachNews has not verified the contents of those tables.
BreachNews is not reproducing customer records, addresses, phone numbers, account identifiers or other personally identifiable information included in the samples.
Administrative and authentication tables also listed
The claimed database includes several tables associated with administrative access and internal application functions.
Among the listed database structures are administrator accounts, login attempts, roles and permissions, two-factor authentication settings, device authentication records and API-related information. Several tables contain fields for IP addresses, session information, authentication keys or other access-control data.
The presence of those fields does not establish that usable credentials or active authentication secrets were exposed. However, if sensitive access material is present and remains valid, the alleged breach could create risks beyond the exposure of customer information.
The threat actor did not explain how the database was obtained or disclose an initial access method.
77 Diamonds operates across Europe and the Middle East
77 Diamonds is an online and showroom-based jeweller founded in 2005 that specializes in made-to-order engagement rings, wedding jewellery and certified diamonds.
The company operates physical showrooms across several international markets while also selling jewellery through 77diamonds.com. Its UK business is operated by 77Diamonds Limited, a company registered in England and Wales.
According to the company’s privacy policy, 77 Diamonds collects personal information through its website and stores customer data on its own systems or through third-party data centers.
Recent records could make the claim more significant
Several customer records displayed as evidence carry creation timestamps from Aug. 23, only 3 days before the breach claim was published.
If authentic, those timestamps could indicate that the dataset originated from a relatively current production environment rather than an old database circulating between threat actors. Database timestamps alone, however, cannot prove when the data was obtained or whether the samples accurately represent the full dataset being offered.
The combination of names, contact details, residential addresses and purchase-related information could create phishing and social engineering risks if the dataset is authentic. Customers of a high-value jewellery retailer could be particularly attractive targets for scams impersonating the company or referencing previous purchases and appointments.
77 Diamonds had not issued any public statement addressing the alleged breach at time of publication.











