The GLAMIRA Breach Happened in December 2023. The Data Just Went Public.
HEROIC analysts identified the GLAMIRA data exposure while cross-referencing a large PII dataset that began appearing in underground marketplaces in late December 2023. The breach was dated December 25, 2023, and confirmed to originate from a database compromise at GLAMIRA, a US-based eCommerce platform specialising in customisable fine jewelry. The incident exposed personal information belonging to 874,681 customers, including full names, email addresses, and phone numbers.
Why This Is Dangerous
GLAMIRA sells high-end, personalized jewelry, which means its customers skew toward higher-income individuals making significant purchases. That makes this breach particularly valuable to criminals. Combining a customer's full name, email address, and direct phone number with the knowledge that they shop at a luxury jewelry retailer creates a perfect toolkit for targeted financial fraud. Scammers can call or text victims pretending to be GLAMIRA, a courier service, or a bank, referencing real purchase history to sound credible. This type of impersonation scam is extremely difficult to detect and increasingly common following retail breaches.
What Was Exposed
- Email Address
- First Name
- Last Name
- Phone Number
Why This Matters
Having your name, email, and phone number exposed together is more dangerous than it might appear. This combination is all an attacker needs to attempt account takeover through social engineering. They can call your mobile carrier, impersonate you, and request a SIM swap, redirecting your phone number to their device. From there, they bypass SMS-based two-factor authentication on your bank and email accounts. Phone number exposure also opens the door to smishing (SMS phishing), robocall fraud, and identity verification bypasses. With nearly 875,000 recieved records in this dataset, the GLAMIRA breach gives criminals a large, pre-qualified pool of fraud targets with known spending power.
How a Database Breach Works
A database breach occured when an attacker finds and exploits a vulnerability in the systems that power an eCommerce website. Retailers store enormous amounts of customer data to manage orders, accounts, and communications, making them high-value targets. Attack methods include SQL injection through checkout or search forms, exploitation of third-party plugins with known security flaws, and compromised administrator credentials. Once inside, the attacker exports customer tables containing names, contact details, and account information. That data is then sold in bulk to fraud rings who use it for phishing, smishing, and identity theft at scale.
Check If You Are Affected
HEROIC's free scanner searches more than 400 billion exposed records, including this GLAMIRA breach. If you have ever shopped at GLAMIRA or used the same email address elsewhere, you should check your exposure now.
Breach Breakdown
874,681 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds