Supply chain
β Supply Chain
Pandora Third-Party Breach (August 2025)
Primary Source βIncident Details
Pandora confirms data breach amid ongoing Salesforce data theft attacks. Danish jewelry giant Pandora has disclosed a data breach after its customer information was stolen in the ongoing Salesforce data theft attacks. Pandora is one of the largest jewellery brands in the world, with 2,700 locations and over 37,000 employees. “We are writing to inform you that your contact information was accessed by an unauthorized party through a third-party platform we use,” reads a Pandora data breach notification sent to customers. Third-party company: Salesforce.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Salesforce
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2025-08-01 Breach occurred
- 2025-08-05 Publicly disclosed