What happened
Jewellery retailer Pandora emailed customers in early August 2025 to say that names and email addresses had been taken after unauthorised access to a third-party platform it uses. Pandora said no sensitive data such as passwords or financial information was exposed and warned recipients to expect phishing. Security press grouped the incident with the ShinyHunters Salesforce data-theft wave that hit several consumer brands the same week.
How the deception worked
Pandora did not describe how the third-party platform was entered, so the social-engineering attribution comes from reporting on the concurrent campaign. That campaign worked by phone: an operator called an employee with CRM access, introduced themselves as internal IT or vendor support, and asked the employee to approve a connected application or read back an authorisation code. The employee saw a genuine vendor consent dialog, which reinforced the caller's story. Because the resulting access was an authorised integration rather than a stolen password, it did not look like an intrusion until large data pulls were noticed.
The control that would have caught it· our reading, not a claim from the sources
Monitor and alert on newly authorised connected apps and on abnormal bulk export volume in marketing and CRM tenants.
Sources (2)
- Pandora and Chanel Customer Data Leaked in Third-Party BreachesPYMNTS·pymnts.comOpen ↗
- Third-Party Data Breach Hits Luxury Fashion Retailers Chanel and PandoraCPO Magazine·cpomagazine.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.