UNOde50 2025 Data Breach

UNOde50 Spanish Jewelry Brand Breach (2025): ~1.6M Customer Contact Records Exposed via WorldLeaks

Company · Jewelry design and retail · Fashion accessories brand · Global

UNOde50 Spanish Jewelry Brand Breach (2025): ~1.6M Customer Contact Records Exposed via WorldLeaks

Spanish jewelry and accessories retailer.

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
22/100
Lower riskHigher risk
Lower: limited current risk based on data value and recency.
Data Sensitivity i
Standard
Exposed data is largely lower-sensitivity. Standard identity-protection precautions are advised.
1.6MRecords
2025Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Classification Tags
World LeaksRansomware / ExtortionRetail & CommerceE-commerceDirect Customers2025

Breach Summary

The WorldLeaks data-extortion group listed Spanish jewelry and accessories brand UNOde50 as a victim on November 14, 2025. Publicly available details are limited and UNOde50 has not issued a detailed confirmation. A DataBreach.com record associated with the incident cited roughly 1.58 million records with email addresses and phone numbers. NOTE: the prior record tagged Social Security numbers as exposed, which is implausible for a Spain-based consumer jewelry brand and unsupported by any source; SSN has been removed as a likely mislabeled field pending verification. No independent confirmation of the exposed data types or count is available.

Full threat analysis, exploitation vectors, and principal guidance below.

11 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

1.6M records analyzed

About UNOde50

UNOde50 is a Spanish jewelry and accessories brand founded in the late 1990s, known for handcrafted, limited-run designs sold through its own boutiques and e-commerce channels internationally. It maintains customer accounts, contact details, order and shipping histories, and loyalty/marketing profiles across retail and direct-to-consumer operations.

Why They Hold Your Data

Jewelry and accessories brands collect customer identity, contact details, addresses, order history, loyalty records, and payment-adjacent data across direct-to-consumer and retail operations.

Recent Developments

The WorldLeaks extortion group listed UNOde50 as a victim on November 14, 2025. As of the latest reporting, details of the exposed data were limited, UNOde50 had not issued a detailed public confirmation, and there was no independent verification of the specific data types or volume.

Data Points Exposed

2 verified field types
Email Address
Phone Number

Breach Impact

For a consumer jewelry brand, the confirmed exposure of customer contact data (emails and phone numbers) primarily enables phishing, smishing, order- and delivery-impersonation scams, and profiling of purchase behavior. Because the brand is luxury-adjacent, exposed customers may be targeted as higher-value households. The breach also carries reputational and GDPR regulatory exposure given the company’s Spanish/EU base.

Exploitation & Downstream Threats

• Targeted phishing and smishing using exposed emails and phone numbers | • Order, delivery, and refund-impersonation scams referencing the brand | • Credential stuffing/account takeover against reused customer passwords | • Profiling/targeting of higher-value households based on luxury purchase behavior

Principal Risk Advisory

What this means for a principal

A consumer-service breach: contact and account data supports phishing, account takeover and profile enrichment. For a high-profile principal the main risk is credible impersonation and enrichment of existing exposure.

What You Should Do

  1. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  2. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
WL
Threat Actor: World LeaksConfidence: High
Extortion-as-a-service / rebrand

Motivation: Financial extortion
A leak extortion operation described as a rebrand or successor evolution of Hunters International. Reporting describes a shift toward extortion-only operations rather than encryption-first ransomware, with affiliate infrastructure and data leak pressure.

Read the full threat-actor profile →

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation