77 Diamonds Customer File Offered With Home Addresses and Appointment Budgets
A forum actor posting as Jurak is selling what they describe as the customer database of 77 Diamonds, a London jeweller selling bespoke engagement and wedding jewellery through its website and showrooms in Mayfair, Manchester and Glasgow. The post claims roughly 690,000 unique email addresses, 461,000 surnames, 409,000 street addresses and 291,000 telephone numbers, alongside wedding dates, dates of birth and marketing preferences. Beyond the customer table, the file list includes showroom appointment records with stated budgets and notes, administrator roles and permissions, admin login attempts with IP addresses, and payment gateway webhook events. No price is given. The claim is unverified.
▣Post details
!What the post claims
- About 690,000 unique emails
- About 461,000 surnames
- About 409,000 street addresses
- About 291,000 phone numbers
- Titles and gender
- Wedding dates
- Dates of birth
- Marketing opt in and opt out
- Account creation dates
- Password column present
- Showroom appointment records
- Stated appointment budgets
- Appointment notes
- Cancellation reasons
- Administrator roles
- Permission assignments
- Admin login attempts
- IP addresses and user agents
- Payment gateway webhook events
◱Screenshots
☷Mapped techniques
The post describes no intrusion method. Both entries are inferred from the artefacts, not stated.
- Collection T1213 Data from information repositories Inferred The table list spans customer, booking, administrative and payment integration areas of one application, which indicates database level access rather than an export from a single interface.
- Exfiltration T1567 Exfiltration over web service Inferred Samples are posted inline and the sale is arranged by direct contact. The route out of the environment is not described.
⚠Potential impact
A jeweller's customer file is not an ordinary retail list. It is a wealth ranked set of names attached to home addresses, and this one comes with the ranking already done: the booking tables record what each customer told the showroom they intended to spend. Combine a stated budget with a delivery address and a phone number and the physical risk is obvious, both to households holding high value items and to the showrooms themselves. Wedding dates make it worse, not better, because they tell an attacker when a purchase is likely to be collected, delivered or worn, and they support extremely convincing social engineering. A message quoting the correct ring, the correct appointment and the correct date sits far outside what most people are prepared to doubt. Two further items need checking against the files. The administrator tables with roles, permissions and login attempt logs would help anyone attempting to get back into the environment, and the payment gateway webhook payloads should be examined for anything beyond tokens, since that is the only place in this set where card related data could plausibly sit.
iStatus Unverified
The sample is detailed and awkward in the ways real data is awkward, with partially completed rows, a mixture of consumer mail providers across several countries, junk test entries and gaps where fields were never filled. The actor also gives separate counts for each field rather than one headline number, which is the behaviour of someone who has actually loaded the file. Most striking is the recency: creation dates in the sample fall within days of the post, which if genuine means the export was taken very recently rather than being an old set repackaged. Against that, no intrusion method, date or access route is described, no price is stated, and the password column, though present, is empty in every visible row, so its storage format cannot be judged. The account is established, with a long history and high standing. Dark Web Informer has not retrieved the data and is not linking it, nor the contact address. 77 Diamonds has not publicly addressed the claim.
Dark Web Informer // Threat Intelligence