levian.com Listed by blackbasta Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The levian.com Listed by blackbasta Ransomware Group (reported May 21, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
People who have bought jewelry from Le Vian, worked with the company, or shared personal or financial details with it may now face questions about whether their information sits among files a ransomware group claims to have taken. Public reporting so far does not confirm how many individuals are involved or exactly which records were copied, yet the listing itself is enough to warrant careful attention from anyone connected to the business.
On May 21, 2024, the ransomware group blackbasta listed levian.com on its leak site, asserting that it had exfiltrated a large volume of internal files. The claim remains unverified by independent confirmation, and the number of people affected is unknown. What is known is limited to the group’s own description of the material and the company’s public profile as a long-established jewelry firm.
Inside the incident
According to the blackbasta listing reported on May 21, 2024, the group claims to have conducted a ransomware attack against levian.com and to have removed internal files before or during the encryption phase typical of such operations. The listing describes the total volume of data as approximately 800 GB and enumerates categories that include accounting records, financial data, corporate data, and personal documents. No further technical details—such as the initial access method, the precise date of intrusion, or whether systems were fully encrypted—have been publicly disclosed. The number of people whose information may be included is listed as unknown. Because the only source for these specifics is the group’s own leak-site post, they must be treated as claims rather than independently Reported Facts.
The group behind it: blackbasta
Blackbasta is a ransomware operation that has been active since roughly mid-2022. Like many contemporary ransomware crews, it typically follows a double-extortion model: encrypting systems while also copying data and threatening to publish or sell it if a ransom is not paid. The group has been observed targeting a range of mid-sized and larger organizations across manufacturing, professional services, healthcare, and retail. Public reporting on prior blackbasta campaigns consistently describes the use of common initial-access techniques, lateral movement inside networks, and the eventual posting of victim names and sample file listings on a dedicated leak site. In the present case the group claims levian.com as a victim and asserts that roughly 800 GB of internal material was taken; no additional statements from blackbasta specifically about this company have been reported beyond that listing.
About levian.com
Le Vian is a family-owned jewelry company whose public history stretches back centuries. Company materials note origins in the fifteenth century and a reputation that, by 1746, led a Persian ruler to entrust the firm with a notable collection of jewels. Today the business operates from 235 Great Neck Road, Great Neck, New York, and maintains a retail and wholesale presence under the levian.com domain. As a purveyor of fine jewelry it routinely handles customer purchase records, payment information, employee data, supplier contracts, and internal financial and accounting files. A breach involving such an organization is consequential because jewelry retailers typically store both high-value commercial data and personally identifiable information belonging to clients and staff.
What was likely exposed
The blackbasta listing states that internal files were exfiltrated and names the categories accounting, financial data, corporate data, and personal documents, with a claimed total size of approximately 800 GB. Beyond those labels, the exact contents remain unconfirmed. Organizations of this type commonly retain customer contact details, transaction histories, credit-card or financing records, employee personnel files, tax documents, inventory and supplier information, and internal correspondence. Whether any or all of those specific record types appear in the claimed 800 GB archive has not been independently verified. Public detail on the precise data elements is therefore limited to the group’s own description.
Why it matters
If the claimed files include personal documents or financial records, individuals could face risks of identity theft, fraudulent account openings, or targeted phishing that references real purchase or employment history. Corporate and accounting data, if authentic, could expose competitive pricing, supplier relationships, or internal financial positions that competitors or fraudsters might exploit. For the company itself, the incident raises the possibility of operational disruption, regulatory notification obligations, and reputational harm among customers who expect discretion around high-value purchases. Because the scale of affected individuals is unknown and the data types are described only at a high level, the practical impact cannot yet be quantified, but the combination of personal and financial material makes the claim material for anyone who has done business with Le Vian.
What to do if you're exposed
Anyone who has purchased from, worked for, or otherwise shared information with Le Vian should monitor bank and credit-card statements for unfamiliar charges and consider placing a fraud alert or credit freeze with the major credit bureaus. Review email accounts for phishing messages that reference jewelry purchases or company contacts, and change passwords on any accounts that reused credentials shared with the firm. Keep an eye on official company notices for Reported Details. Readers can also run a free exposure scan of their email address to check whether their information has already appeared in known breach data sets.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
schuff.com Listed by blackbasta Ransomware Groupgfemlaw.com Listed by blackbasta Ransomware Groupandyfrain.com Listed by blackbasta Ransomware Groupsuit-kote.com Listed by blackbasta Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the levian.com Listed by blackbasta Ransomware Group →
Publicly posted by blackbasta — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.