Ransomware victim disclosure
← All victimsCleor
Claimed by Thegentlemen · listed 2 months ago
Status timeline
- ListedApr 14, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- France
- Listed on leak site
- Apr 14, 2026
About the victim
AI dossier — public-source company profileCleor is a historic French jewelry brand with over 20 years of experience, selling jewelry, watches, and accessories for men, women, and children through its online store and physical boutiques across France. The company controls its full production chain, from raw material sourcing to creative design and assembly, specializing in precious materials including 18K gold, diamonds, pearls, and gemstones. It operates both as an e-commerce retailer and a brick-and-mortar jewelry chain in France.
- Industry
- Luxury Goods & Jewelry
- Employees
- 51-200
Attack summary
Severity: high — Data has been published (not merely listed), indicating confirmed exfiltration from a consumer-facing e-commerce jewelry retailer likely holding customer PII and potentially payment data at scale.The group 'thegentlemen' claims to have compromised Cleor and has published data (disclosed status: data_published), indicating exfiltration of company data; no ransom amount or specific data volume was stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Customer records
- Order data
- Business/operational data
- Potentially payment or personal information
What the group claims
cleor.com zoominfo.com/c/cleor/355616744 CLEOR is a historic French jewelry brand with over 20 years of experience, offering jewelry, watches, and accessories for men, women, and children online and in stores across France. They control the full production chain — from raw material sourcing to creative design and assembly — with a focus on quality precious materials (18K gold, diamonds, pearls, gemstones) at fair prices
Sources
- Victim sitecleor.com
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

