Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Pandora

Pandora Vendor Cyber Rating & Cyber Score

pandoragroup.com

Pandora is the world’s largest jewellery brand. The company designs, manufactures and markets hand-finished jewellery made from high-quality materials at affordable prices Pandora jewellery is sold in more than 100 countries through more than 6,500 points of sale, including more than 2,500 concept stores. Headquartered in Copenhagen, Denmark, Pandora employs 32,000 people worldwide and crafts its jewellery at two LEED-certified facilities in Thailand using mainly recycled silver and gold. Pandora is committed to leadership in sustainability and has set science-based targets to reduce greenhouse gas emissions by 50% across its own operations and value chain by 2030. The company is listed on the Nasdaq Copenhagen stock exchange and


Pandora A.I CyberSecurity Scoring

Pandora
Company Information
Website:http://www.pandoragroup.com
Employees number:21,855
Number of followers:583,608
NAICS:4483
Industry Type:Retail Luxury Goods and Jewelry
Homepage:pandoragroup.com
Pandora Risk Score (AI oriented)
Between 600 and 649
logo
PandoraRetail Luxury Goods and Jewelry
Updated:
05/09/2026
633/1000
Poor
Caa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
✖ Insurance prefers TPRM score to calculate premium
Pandora Global Score (TPRM)
xxxx
logo
PandoraRetail Luxury Goods and Jewelry
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

PandoraPoor
Current Score
633Caa (POOR)
01000
3 incidents
-50 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
636Before Incident
SEPTEMBER 2026
634Before Incident
AUGUST 2026
631Before Incident
JULY 2026
628Before Incident
JUNE 2026
752Before Incident
MAY 2026
751Before Incident
APRIL 2026
750Before Incident
MARCH 2026
750Before Incident
FEBRUARY 2026
749Before Incident
JANUARY 2026
702Before Incident
DECEMBER 2025
702Before Incident
NOVEMBER 2025
651Before Incident
Breach
24 Nov 2025 • Pandora
Salesforce

Salesforce Data Breach: ShinyHunters Hack via Gainsight Integration

601After Incident
CRITICAL-50
GAI1122911112425
The Salesforce data breach involved the ShinyHunters (UNC6240) hacking group, which exploited stolen OAuth tokens from Salesloft’s GitHub account to infiltrate Drift’s Salesforce integration and subsequently compromise Gainsight, a customer process management platform. The attackers gained unauthorized access to over 200 Salesforce instances, exfiltrating enterprise customer data through third-party service integrations (including HubSpot and Zendesk). While Salesforce revoked access keys and removed affected apps from the AppExchange, the breach exposed sensitive customer data, though the full scope of the leak remains undisclosed. The attack leveraged supply-chain vulnerabilities rather than a direct Salesforce platform flaw. ShinyHunters claimed delayed detection (1–2 weeks post-intrusion) and sought internal accomplices for further exploitation. Salesforce refused ransom demands, but the incident highlights risks in third-party integrations and credential-based attacks.
INCIDENT DETAILS -
TYPE
Data BreachUnauthorized AccessSupply Chain Attack
MOTIVATION
Data TheftExtortionFinancial GainEspionage
IMPACT
Salesforce Instances (200+)GainsightSalesloftDriftHubSpotZendeskTemporary Disruption of Gainsight Apps on Salesforce AppExchangeLimited Functionality of HubSpot/Zendesk ConnectorsRevocation of Access KeysRemoval of Gainsight Apps from AppExchangeInternal Reviews by Affected CompaniesPotential Erosion of Trust in Salesforce EcosystemNegative Publicity for Gainsight, HubSpot, ZendeskHigh (Enterprise Customer Data Exposed)
DATA BREACH
Enterprise Customer DataCRM RecordsIntegration LogsSensitivity Of Data: High (Potential PII, Business-Critical CRM Data)Personally Identifiable Information: Likely (Enterprise Customer Data)
AUGUST 2025
800Before Incident
Breach
06 Aug 2025 • Pandora
Pandora

Pandora Data Breach via Third-Party Vendor

743After Incident
CRITICAL-57
PAN401080725
Danish jewellery giant Pandora disclosed a significant data breach involving a third-party vendor platform. The breach exposed customer names, phone numbers, and email addresses, but no passwords or payment data were accessed. The incident was contained swiftly, with no evidence of data exfiltration or public distribution. Pandora has warned customers about potential phishing attempts and is conducting a forensic analysis to determine the full scope of the compromise.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Customer names, phone numbers, and email addressesBrand Reputation Impact: Potential phishing risks and customer vigilance requiredIdentity Theft Risk: Low (no sensitive authentication credentials accessed)Payment Information Risk: None
DATA BREACH
Type Of Data Compromised: Personally Identifiable Information (PII)Sensitivity Of Data: Low (no passwords or payment data accessed)Data Exfiltration: No evidence of data exfiltrationPersonally Identifiable Information: Customer names, phone numbers, and email addresses
AUGUST 2025
800Before Incident
Breach
01 Aug 2025 • Pandora
Gainsight

Gainsight Unauthorized Salesforce Data Access via Stolen OAuth Tokens

690After Incident
CRITICAL-110
GAI0292402112125
The incident at Gainsight stemmed from a downstream effect of the August 2025 Salesloft breach, where the Scattered Lapsus$ Hunters group stole OAuth tokens tied to Salesloft’s Drift AI chat integration with Salesforce. These tokens granted unauthorized API access to 760 Salesforce instances, leading to the exfiltration of 1.5 billion records, including passwords, AWS keys, and Snowflake tokens.A subgroup, ShinyHunters, exploited the stolen credentials to breach Gainsight’s systems, extracting customer contact data (names, business emails, phone numbers, regional details), licensing information, and support case contents. Salesforce responded by revoking all active Gainsight-associated tokens and temporarily removing its apps from the AppExchange to mitigate further exposure. While Salesforce clarified that its platform itself was not vulnerable, the breach originated from Gainsight’s external app connections, compromising sensitive corporate and customer data across hundreds of organizations.
INCIDENT DETAILS -
TYPE
Data BreachUnauthorized AccessCredential Theft
MOTIVATION
Data TheftFinancial Gain (Potential Dark Web Sale)Reputation Damage
IMPACT
Salesforce Instances (760 in Salesloft breach)Gainsight-published ApplicationsToken RevocationAppExchange RemovalCustomer NotificationsLoss of TrustNegative PublicityBusiness Contact Details Exposed
DATA BREACH
Business Contact Details (Names, Emails, Phone Numbers)Licensing InformationSupport Case ContentsRegional/Location DetailsPasswords (Salesloft Breach)AWS Keys (Salesloft Breach)Snowflake Tokens (Salesloft Breach)1.5 Billion (Salesloft Breach)Undisclosed (Gainsight Breach)Moderate to High (Business PII, Credentials, API Keys)Business PII (Names, Emails, Phone Numbers)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Pandora ?
?
What was Pandora's A.I Rankiteo Cyber Score in September 2026 ?
?
What was Pandora's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Pandora's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Pandora's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Pandora's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Pandora's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Pandora's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Pandora's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Pandora's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Pandora's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Pandora's A.I Rankiteo Cyber Score in November 2025 ?
?
What is the average per-incident point impact on Pandora's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Pandora ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Pandora's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?