On August 5, 2025, global jewelry giant Pandora confirmed it suffered a cyberattack through a third-party platform used to store customer data.
According to Forbes, the attackers obtained basic personal information, including names and email addresses. No passwords, credit card details, or other sensitive financial information were compromised, Pandora said.
The company has contained the breach and strengthened its security measures, and there’s currently no evidence the data has been leaked or misused.
The exposed data, though seemingly harmless, can still be weaponized in dangerous ways. The company urges impacted customers to be wary of unsolicited correspondence and potential phishing attacks stemming from the breach.
“However, as a precautionary measure, we recommend that you pay extra attention to unusual emails and online activities prompting for your data as this could be phishing attempts from third parties pretending to be associated with Pandora,” the company said.
Source: Forbes
With a name and email, attackers can craft personalized, highly convincing messages, mimicking Pandora or other trusted brands to trick victims into clicking malicious links or divulging confidential information.
Even without compromised passwords, email addresses alone can be tested across platforms where users may have reused weak credentials.
How to stay safe:
Check our free password generator here.
As cyberthreats like phishing and data breaches spread, Bitdefender offers a multi-layered approach to digital safety:
tags
Alina is a history buff passionate about cybersecurity and anything sci-fi, advocating Bitdefender technologies and solutions. She spends most of her time between her two feline friends and traveling.
View all postsMay 16, 2025