Hackers say they know where nearly half a million diamond customers live
Bought a diamond ring? Attackers say they know where you live.

Image by Cybernews
- A hacker claims data from 77 Diamonds includes more than 409,000 home addresses.
- Cybernews reviewed samples, but they showed emails, some names, and phone numbers, not home addresses.
- Researchers could not verify whether referenced database tables belong to 77 Diamonds.
- If confirmed, customers may face phishing attempts because jewelry purchases can signal high-value targets.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Over half a million diamond shoppers may have been affected by the alleged data breach.
The London-based online jewelry retailer 77 Diamonds, which specializes in diamonds and engagement rings, has allegedly been breached. While few details are known at this point, a threat actor is boasting on a hacker forum that the affected customer count may exceed half a million.
According to the claims, the attackers have around 690,000 unique email addresses, more than half of which are paired with last names, and over 409,000 home addresses.
The threat actor added 20 sample records that allegedly reference customers. Cybernews researchers have examined the samples and found that the most sensitive information visible in them consisted primarily of email addresses, with some records also containing full names and phone numbers.
The samples did not contain home addresses, despite the seller claiming to possess hundreds of thousands of them.
The threat actor also referenced several other database tables allegedly included in the stolen dataset. Those references include table and field names, but the seller did not provide samples from those portions of the alleged database.
As a result, Cybernews could not independently verify what information those tables contain or whether they actually belong to 77 Diamonds.
The attacker also references an order-item table that includes fields for jewelry measurements. Those fields provide a possible connection to a jewelry retailer, but they do not directly identify 77 Diamonds. No brand name was visible in the data examined by our researchers.
If the claims prove to be legitimate, the affected customers may be at risk of phishing and social engineering attacks. Customers interacting with a jewelry retailer could indicate to potential attackers high-value targets.
The alleged database also contains references to Stripe as a payment method. This could be related to the exposure of Stripe data, which affected multiple shops using the service.
Cybernews has reached out to 77Diamonds for comment, but a response is yet to be received.