Leo Schachter Diamonds Data Breach

Alleged

Ransomware claim involving Leo Schachter Diamonds.

Published: Sep 5, 2026 TheGentlemen
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Leo Schachter Diamonds
Industry
E-Commerce
Threat Actor
TheGentlemen
Date of Incident
Sep 5, 2026

Executive Summary

Thegentlemen ransomware operation listed Leo Schachter Diamonds on its leak site on September 5, 2026, as identified by SOCRadar’s Dark Web Monitoring service. Leo Schachter Diamonds, a US-based manufacturer and wholesaler of diamonds, operates within the global luxury jewelry market. This sector is particularly susceptible to ransomware and extortion attacks due to the high value of data (including trade relationships, supplier chains, and high-net-worth client records) and the significant reputational damage that an incident could cause, thereby increasing the likelihood of ransom payment. Thegentlemen has been highly active recently, claiming 237 victims in the last 60 days. Their primary targets are organizations within the Manufacturing, Technology, and Retail sectors, with a significant presence in the United States, United Kingdom, and India. Previous victims in the US retail and commerce sector include Northwest Trophy, Gravity Coffee, National Furniture Outlet, and The Sole. Leo Schachter Diamonds’ inclusion signifies the group’s targeting of premium luxury goods, a market segment that offers substantial incentives for companies to maintain discretion and potentially comply with demands due to the sensitive nature of their customer data and business operations.

Technical Analysis

A SOCRadar stealer-log query for the domain leoschachter[.]com returned no matching records. It is important to note that this query has limitations; the absence of positive findings does not conclusively indicate that the organization is unaffected. Compromised credentials may still exist if they were associated with personal aliases, alternate corporate domains not included in the sampled dataset, or if the indexed records predate a recent credential rotation. Thegentlemen’s typical modus operandi involves leveraging credentials harvested via infostealers as a primary method for initial access. These credentials are often validated and used to gain entry through Microsoft 365, VPNs, or remote-access portals before ransomware deployment. The lack of positive telemetry in this instance does not preclude such an attack vector from having been employed. Continued monitoring of dark web stealer feeds and a thorough review of credential hygiene practices, including password rotation and multi-factor authentication checks, are recommended to mitigate potential risks.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.