
Renowned jewellery brand Pandora said that it experienced a major data security breach, compromising the sensitive personal information of its customers.
Considered as one of the world’s largest jewellery brands, Pandora sells its products in over 100 countries through thousands of points of sale, including concept stores.
Recently, Pandora started notifying its customers via email about a data security incident. The breach took place when an unauthorised threat actor gained access to a vendor platform used by the company to manage customer data.
"Common types of data" aka legally defined Personal Data and as such an important breach of security, being downplayed, by Pandora. #fail pic.twitter.com/HxXvxgOPiF
— myPhilTaylor (@myPhilTaylor) August 5, 2025
The fashion jewellery house immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
“We are writing to inform you that Pandora has experienced a cyber security attack, where some customer information was accessed through a third-party platform that we use. We want to reassure you that the attack has been stopped, and as a result we have further strengthened our security measures,” Pandora said.
While Pandora did not share details on when its service provider’s network was breached, the jewellery house confirmed that the compromised data included “very common types of data” like names, dates of birth and email addresses.
“We’d like to stress that no passwords, credit card details or similar confidential data were involved in this incident,” the company added.
While Pandora found no evidence of the compromise data being misused, it has advised all affected individuals to remain vigilant and “ pay extra attention to unusual emails and online activities prompting for your data as this could be phishing attempts from third parties pretending to be associated with Pandora.”
French luxury fashion house Chanel recently reported a similar cybersecurity incident, in which an unauthorized threat actor gained access to a third-party vendor platform used by the company to manage and store customer data.
According to the email sent to affected customers, the breach was discovered on July 25, when threat actors infiltrated the network of one of its vendors. After an investigation, the company determined that the sensitive personal information of its customers including names, addresses, phone numbers, and email addresses were exposed during the breach.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543