Technology

Graff’s Ransomware Payment Not an Unusual Move, Expert Says

TechnologyJul 12, 2022

Graff’s Ransomware Payment Not an Unusual Move, Expert Says

The high-end jeweler reportedly paid a $7.5 million ransom to a group of hackers and is suing its insurance company to cover the loss.

London—Graff Diamonds reportedly paid a $7.5 million ransom in Bitcoin to the hackers responsible for a ransomware attack on its systems last fall, a decision that is not unusual for large companies today, one expert says.

Ransomware is malware that uses encryption to hold a victim’s system or personal data hostage, basically, and demands payment to get them back.

Following the attack on Graff, Conti, the group that took credit for it, leaked data about the brand’s clients, such as their names and, potentially, their home addresses.

Graff counts many high-end clients and celebrities as customers, and the data breach included leaked data about the royal families in Saudi Arabia, the United Arab Emirates, and Qatar, prompting Conti to issue an apology to the families involved, an unusual move for the group.

Conti threatened to leak more of Graff’s data if the ransom wasn’t paid.

Though it tried to avoid paying, the high-end jeweler eventually offered $7.5 million, half the original ransom amount, and Conti accepted, according to Bloomberg, which broke the story. The jeweler paid in Bitcoin. 

Graff is also suing its insurance company, The Travelers Companies Inc., in a London court for the losses, arguing that its policy should cover the ransom payment. 

“The criminals threatened targeted publication of our customers’ private purchases. We were determined to take all possible steps to protect their interests and so negotiated a payment that successfully neutralized that threat,” a Graff spokesperson told National Jeweler. 

“Regrettably, these commercial decisions are all too common these days. Insurers know this, which is why we are extremely frustrated and disappointed by Travelers’ attempt to avoid settlement of this insured risk. They have left us with no option but to bring these recovery proceedings at the High Court.”

The Travelers Companies did not respond to a request for comment by press time.

 Related stories will be right here … 

Shayne Caffrey, marketing manager and cybersecurity awareness training lead for LeeShanok Network Solutions, echoed what Graff Diamonds said it its statement—ransom payouts like this are fairly common today.

“Deciding whether to pay the ransom is a cost/benefit analysis. It can make a lot of sense to pay up when you can’t safely restore from a backup,” he said in an email to National Jeweler.

Once a business does decide to pay, it becomes a negotiation, going back and forth on price like in any deal until it becomes worth it for both sides. 

“In this case, the initial $15 million demand may not have been worth it, but $7.5 million was,” Caffrey said. “Hackers would rather get something than nothing. This calculated approach means ransoms get paid more often than any of us would like.”

He also noted there’s rarely a guarantee that hackers will unencrypt the data even once the ransom is paid.

Caffey offered businesses two recommendations to reduce the chances of becoming a victim of cybercrime.

The first is to require every employee to undergo cybersecurity awareness training annually, with a particular focus on phishing prevention.

According to IBM, 95 percent of breaches result from human error, and the only way to fix that is through education, he noted.

But rather than using the common online training modules, Caffrey suggested bringing in a cybersecurity expert to deliver a live training, either in-person or virtually.

“In my experience, those trainings are much stickier.”

The second tip is to create a strong Backup and Disaster Recovery (BCDR) Strategy.

“Implementing these strategies can seem expensive on the surface, but they are often a fraction of the cost of paying a ransom, or even paying increased insurance premiums after a breach,” Caffrey said.

“Plus, it feels a lot better to restore your environment to a pre-ransomware instance than to reward the hackers by paying a ransom.”

More tips businesses can use to protect themselves from the Jewelers Security Alliance can be found in National Jeweler’s original story reporting on the Graff attack.
Brecken Branstratoris the senior editor, gemstones at National Jeweler, covering sourcing, pricing and other developments in the colored stone sector.

The Latest

AuctionsSep 27, 2022
In Betty White’s Blockbuster Estate Sale, Jewelry Held Its Own

Fine jewelry comprised three of the auction’s top 10 lots, though it could not top her director’s chair or scripts from “The Golden Girls.”

CrimeSep 27, 2022
3 Suspects in Beverly Hills Smash-and-Grab Robbery Arrested

A total of four suspects are now in custody with police still on the lookout for the remaining two.

ColumnistsSep 27, 2022
Creative Connecting: Fun Ideas for Holiday 2022 In-Store Events

From a “whodunnit” murder mystery to a permanent jewelry party, Duvall O’Steen and Jen Cullen Williams share a wealth of suggestions.

Brought to you by
6 Steps to Start a Dynamic Company Culture

Learn how to better serve your employees, customers and community by having a dynamic and supportive company culture.

MajorsSep 27, 2022
Stuller Releases 2 Updated Catalogs Ahead of the Holiday Season

“Mountings 2023-2024” and “Diamonds & Gemstones 2023-2024” offer a vast selection of options to create custom pieces.

Weekly QuizSep 22, 2022
This Week’s Quiz
Test your knowledge of the latest jewelry news with this quick test.
Take the Quiz
Events & AwardsSep 27, 2022
ICA’s 2023 Congress Will Be Held in Dubai

The event will be hosted by the Dubai Multi Commodities Centre from Feb. 15-17.

IndependentsSep 26, 2022
Roberson’s Fine Jewelry to Close After 42 Years

The store’s liquidation sale will showcase the mix of classic and unique jewels it’s known for stocking.

Brought to you by
Committing to an Ethical Diamond Business

While ethical mining is essential to a diamond business, they represent only a fraction of the responsibility bestowed on jewelers.

CollectionsSep 26, 2022
Go ‘Inside the Dream’ of Bulgari Via a New Documentary on Amazon Prime

It follows Creative Director Lucia Silvestri as she crafts the brand’s high jewelry collections.

Recorded WebinarsSep 26, 2022
Watch: What Jewelers Should Know About Insurance

From safeguarding showcases to appraisal liability, insurance experts Mark Devereaux and Andrew Chipman share insurance tips for jewelers.

TrendsSep 26, 2022
Vahan Collabs With Wolf on a Jewelry Box

It’s the first time in 50 years the brand has made something other than jewelry.

Events & AwardsSep 26, 2022
Texas Jewelers Association Rolls Out New Format for Design Competition

The competition takes place in tandem with TJA’s annual convention, known as the Texas Jewelers Roundup.

CollectionsSep 23, 2022
Pandora Reimagines Keith Haring’s Art in New Collection

The limited-run collection features figures from Haring’s iconic street art on charms, bracelets, rings, and more.

GradingSep 23, 2022
GIA Career Fair Returns to Carlsbad

The Gemological Institute of America also announced plans for events in New York and London in 2023.

SourcingSep 23, 2022
See the Items in Gem Legacy’s 4th Anniversary Benefit Auction

One hundred percent of proceeds will benefit the nonprofit’s silicosis prevention initiative.

CollectionsSep 23, 2022
Piece of the Week: Emily Weld Collins’ Amulet

Inspired by antique coins, it depicts a “hippocamp” from Greek mythology.

EditorsSep 22, 2022
4 Things Seen and Heard at the 2022 HardRock Summit

Gemstones Editor Brecken Branstrator dishes on the latest color to trend, the show floor buzz, and more from Denver.

TrendsSep 22, 2022
There’s a New Book on Tiffany & Co.

Written by historian Vivienne Becker, it accompanies this summer’s Tiffany jewelry exhibition at London’s Saatchi Gallery.

Supplier BulletinSep 22, 2022
Using Commerce Data to Outshine the Competition in the Jewelry Industry

Sponsored by Bloomreach

SourcingSep 22, 2022
First Diamond Recovered From Burgundy’s Ellendale Restart

Burgundy also announced the retail launch of its diamond brand, Maison Mazerea.

Events & AwardsSep 22, 2022
JCK Industry Fund Now Accepting Applications

Organizations with a project or initiative aimed at bettering the jewelry industry are encouraged to apply.

Lab-GrownSep 21, 2022
An Updated Look at the Lab-Grown Diamond Market: Size, Pricing, and More

As the end of 2022 draws near, National Jeweler offers another deep dive into lab-grown diamond market data.

TrendsSep 21, 2022
These Are the Diamond Jewels to Stock for the Holidays

These trending-yet-timeless pieces are no-brainers for customers in search of the perfect gift.

SourcingSep 21, 2022
A Day in the Life: Daniel Namdar, Fancy Color Diamond Specialist

Namdar joins a long line of diamond experts, but his love of the trade was learned rather than inherited.

Lab-GrownSep 21, 2022
Looking Ahead: 4 Factors That Could Shape Lab-Grown Diamonds’ Future

Growing supply and falling prices likely will make differentiation a necessity and a reality, according to analyst Paul Zimnisky.

AuctionsSep 21, 2022
Egyptomania at Sotheby’s: See the Egyptian Revival Jewels Heading to Auction

The auction house is celebrating 100 years since the discovery of King Tut’s tomb.

MajorsSep 21, 2022
Claire’s Expands Walmart Partnership

The chain’s jewelry and accessories are now available in 2,500 Walmart locations.

×

This site uses cookies to give you the best online experience. By continuing to use & browse this site, we assume you agree to our Privacy Policy