LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Charm Diamond Centres Listed by akira Ransomware Group

HIGH severity claimedUnverified claimHow we verify

Charm Diamond Centres Listed by akira Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 23, 2025
Charm Diamond Centres Listed by akira Ransomware Group

Reported September 23, 2025.

HIGH
Severity
September 23, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Charm Diamond Centres was listed by the akira ransomware group on September 23, 2025, after internal files were exfiltrated. Individuals are urged to check whether their information was involved and to take protective steps.

Severity & verification
HIGH severity claimedUnverified claim
Exposes government-ID data.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Charm Diamond Centres, a Canadian jewellery retailer, has been listed by the Akira ransomware group as a victim of a cyber attack, according to a report dated September 23, 2025. Public details remain limited: the number of people affected is unknown, and the incident is described as involving the exfiltration of internal files in a ransomware attack. The group claims it will upload almost 19 GB of corporate data, including employee information, financials, and client files.

For customers, employees, and partners of a jewellery chain that holds personal and financial records, any confirmed exposure of such material carries practical risks of identity misuse and fraud. At this stage the listing itself is an unverified claim by the threat actor, and independent confirmation of the full scope has not been publicly established.

Breaking down the breach

According to available reporting, Charm Diamond Centres appeared on the Akira ransomware group's leak site. The organisation is identified as a jewellery retailer, and the incident is characterised as a ransomware attack in which internal files were allegedly exfiltrated. No public confirmation has been provided of the exact date the intrusion began, the initial access method, or whether systems were encrypted in addition to data theft.

The group has stated that it will upload almost 19 GB of corporate data. It has listed categories that include employee information (passports, driver's licences, health information and similar records), financials, clients' files, projects and NDAs. The number of individuals potentially affected remains unknown, and no further technical indicators or forensic findings have been released in the public record. All specifics beyond the listing and the group's own description are therefore undisclosed.

Who is akira?

Akira is a ransomware operation that became active in 2023 and has since conducted double-extortion campaigns against organisations across multiple sectors. The group typically gains access, steals data, and then threatens to publish the material on a dedicated leak site if a ransom is not paid. It has been observed using both Windows and Linux encryptors and has targeted manufacturing, education, professional services and retail entities, among others.

In this case the group claims Charm Diamond Centres as a victim and has announced the forthcoming release of nearly 19 GB of corporate data. Those statements are claims made on the leak site; they have not been independently verified in the public reporting available to date. Akira's established pattern is to pressure victims by publicising stolen files, but the accuracy and completeness of any particular dump can only be assessed once material is released and examined.

Charm Diamond Centres and its sector

Charm Diamond Centres is a jewellery retailer founded in Nova Scotia by Richard Calder in 1972 and remains owned and operated by the Calder family. As a multi-location retail chain specialising in diamonds and fine jewellery, it operates in a sector that routinely processes customer purchase records, payment details, identification documents for high-value transactions, and employee personnel files.

Retail jewellery businesses typically maintain databases of client contact information, transaction histories, warranties and, in some cases, financing or credit arrangements. They also hold internal corporate records such as contracts, supplier agreements and staff data. A breach affecting such an organisation is consequential because the combination of personal identifiers and financial records can be used for fraud, and because the loss of client trust can affect ongoing commercial relationships. Public detail on the precise systems compromised at Charm Diamond Centres has not been released.

The information in question

Reporting states that internal files were exfiltrated. The Akira group claims the material includes employee information such as passports, driver's licences and health information, as well as financials, clients' files, projects and NDAs, amounting to almost 19 GB. These categories are presented as the group's own description of what it intends to publish; they have not been independently confirmed as the complete or exact contents of any archive.

Organisations of this type commonly hold customer names, addresses, purchase histories, payment-card or financing data, employee payroll and identity documents, and internal business records. Because the precise data types and volumes remain unconfirmed beyond the group's claims, it is not possible to state with certainty which specific records, if any, have been exposed. The absence of an official disclosure from the company leaves the exact composition of the alleged data set unknown.

The real-world impact

If the claimed employee records contain identity documents and health information, affected staff could face elevated risks of identity theft, fraudulent account openings or medical-identity misuse. Client files, if they include personal and financial details, could enable targeted phishing, account takeover attempts or unauthorised credit applications. Financial and contractual documents could also be used for competitive intelligence or further social-engineering attacks against the company and its partners.

For the organisation itself, the incident may lead to operational disruption, regulatory scrutiny under Canadian privacy law, and the need to notify individuals and authorities once the scope is clarified. Because the number of people affected is unknown and the data set is unconfirmed, the full scale of individual harm cannot yet be quantified. The primary near-term risks remain opportunistic fraud and the long-term erosion of customer and employee confidence.

What to do if you're exposed

Anyone who has been a customer or employee of Charm Diamond Centres should monitor bank and credit-card statements for unfamiliar activity and consider placing a fraud alert or credit freeze with the major Canadian credit bureaux. Review any recent communications that request personal or payment information, and treat unsolicited messages claiming to relate to the incident with caution. If you supplied identity documents for a high-value purchase or financing, be especially alert to signs of identity theft.

Change passwords on any accounts that may have reused credentials associated with the retailer, and enable multi-factor authentication where available. Readers can also run a free exposure scan of their email address to check whether their information has already appeared in known breach data sets. Official guidance from Charm Diamond Centres or Canadian privacy regulators, once issued, should be followed for any specific notification or remediation steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyCharm Diamond Centres security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Charm Diamond Centres’s full breach history →

More recent breaches

Bell Lifestyle Products Listed by akira Ransomware GroupDecember 11, 2025Turf Care Store Listed by akira Ransomware GroupSeptember 29, 2025HBI Canada Listed by akira Ransomware GroupJune 5, 2025Arbour Volkswagen Listed by akira Ransomware GroupMay 26, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Charm Diamond Centres Listed by akira Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by akira — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram