Austrian jeweller FREYWILLE discloses breach as Aurora claims data theft (2026)
Luxury enamel-jewellery maker FREYWILLE disclosed a cyberattack on 6 August 2026 after detecting unauthorised activity, as the Aurora ransomware group claimed to have stolen customer and employee data.
- Victim
- FREYWILLE
On 6 August 2026, FREYWILLE β the Vienna-based maker of hand-painted fire-enamel luxury jewellery β disclosed a cyberattack after detecting unauthorised activity in its IT systems four days earlier. The company warned that data had likely been compromised and said its investigation into the full scope of the intrusion was ongoing.
What happened
FREYWILLE said the potentially affected information included customer contact, contract, communication, and billing details, as well as personal information belonging to former employees. Shortly after the disclosure, the Aurora ransomware group listed FREYWILLE on its dark-web leak site and claimed to have exfiltrated internal company data. The group alleged access to more than 140 employee files containing sensitive material β salary documentation, social-security records, cross-border employment contracts, passport copies, and other personnel records β as well as business and legal documents including product-costing records, proprietary enamel colour formulations, and litigation files.
FREYWILLE has not publicly attributed the incident to Aurora, and the group's claims about the volume and nature of the stolen data had not been independently verified at the time of disclosure.
Why it matters
The FREYWILLE case illustrates how mid-sized luxury manufacturers β brands with valuable trade secrets but leaner security teams than multinationals β have become attractive targets for extortion crews. Beyond the reputational risk of exposed customer records, the alleged theft of proprietary enamel formulations and product-costing data points to a form of intellectual-property loss that is hard to remediate: unlike a leaked password, a stolen manufacturing recipe cannot simply be reset.
Timeline
FREYWILLE detects unauthorised activity within its IT systems.
FREYWILLE discloses the cyberattack, warning that data was likely compromised; the Aurora ransomware group lists the company on its leak site.
Sources
- dexpose.iohttps://www.dexpose.io/aurora-ransomware-group-strikes-austrian-jewelry-brand-freywille/
- malware.newshttps://malware.news/t/aurora-ransomware-group-strikes-austrian-jewelry-brand-freywille/124789
- redpacketsecurity.comhttps://www.redpacketsecurity.com/aurora-ransomware-victim-freywille/