- Scammers swindled close to €1.1 million from a French couple by convincing them their assets were at risk due to an alleged data breach of a precious metal firm.
- The incident is part of a growing trend in which hackers combine real or fake data breaches with social engineering tactics to steal from rich people who own either gold, cash or other valuables.
- The scam comes after a French precious metals firm, Achat-Or-Et-Argent.fr, reported a security threat. It raises fears that customer information tied to valuable assets can become a tool for fraud.

A retired couple living in Yvelines, just outside Paris, lost nearly €1.1 million approx. $1.3 million, to a sophisticated scam. The scheme started with an alleged data leak tied to a well-known precious metals dealer.
This couple believed criminals got access to customer details from Godot & Fils, the French gold and silver dealer, where they’d bought investment gold years before.
Investigators say the scammers told the couple that the company sent them to protect their valuables after the data breach. The scammers added pressure and urgency to the situation.
The couple feared they could lose their assets so to prevent that, they handed over cash, jewelry, gold bars, and precious stones worth €1.1 million to the scammers.
Now, French authorities are digging into the case. They’ve launched an investigation into organized fraud. The aim is to find out if other Godot & Fils customers fell victim to the same scheme.
Scammers Exploit Victims’ Fear and Trust
Unlike most online scams that use deceptive emails or phishing links, the latter required some psychological pressure from the scammers.
Reports noted that the scammers made contact with the retired couple and told them that the customers’ details at Godot & Fils were compromised and that criminals would soon break into their home and steal everything valuable.
The fake security agents then offered what sounded like a simple solution. They claimed they would keep the valuables in “secure custody” until the danger was over.
On believing the claim, the couple handed over their wealth to the crooks. But before they were able to recognize their mistake, the fraudsters had made off with close to €1.1 million of their assets.
French authorities are investigating this case as a case of organized crime. They suspect it may involve a structured criminal network and not individual scammers.
Data Breaches Fuel Real-World Crimes
Authorities haven’t said outright that Godot & Fils suffered a data breach that may have fueled this case. What’s clear is that scammers claimed customer information was compromised, and that’s how they earned victims’ trust.
Investigators still don’t know if the criminals actually got their hands on real customer data or just did their homework on the couple’s gold purchases.
This whole thing points to a bigger shift in cybercrime. Thieves aren’t just using stolen info for identity theft or basic financial scams anymore. Now, they use personal details to make their tricks sound believable.
If scammers know someone bought investment gold or something similar, it gives them enough detail to create a story that feels real. And that’s often all it takes for someone to hand over money or valuables, no threats needed.
Another French Precious Metals Firm Reported a Security Incident
The investigation also comes after another company in France’s precious metals sector disclosed a cybersecurity incident earlier this year.
Achat-Or-Et-Argent.fr (Gold and Silver Purchase), a French company specializing in buying and selling investment gold and silver, recently informed customers about a security breach. The incident involved unauthorized access to part of its information system. The company detected the access and stopped it quickly after discovery.
The company conducted a thorough technical analysis following the breach. They have reported the incident to France’s data watchdog, CNIL, and also filed a complaint with appropriate agencies. Other security measures are currently in place to boost their security.
Achat-Or-Et-Argent.fr provides services to individuals and investors looking to buy or sell precious metals. The company’s structure ensures that it becomes a very desirable target for cybercriminals due to its valuable information. According to the company, analysis shows the breach didn’t affect any of its central systems or main database.
The breach may have exposed names, email addresses, phone numbers, postal addresses, and purchase history. This is all personal data that Achat-Or-Et-Argent.fr has put together to form profiles of customers who want to invest in precious metals.
However, the firm claims that the attack didn’t affect sensitive data. Also, there was no impact on bank details, passwords, regulatory paperwork, or sensitive financial data.
But even though financial credentials remain secure, the leaked information is still dangerous. Criminals can use names, contact information, and order history for attacks.
The nature of the company’s business adds extra risk. That’s because the customers are people who have purchased valuable assets like gold and silver.
High-Value Customer Lists are Attractive Targets
Businesses that provide services on gold, silver, and precious metals investing accumulate a lot of personal information about their clients. Such information can be names, addresses, purchase records, transaction history, and much more.
The risks extend beyond precious metals, a recent breach claimed by hackers targeted France’s Fédération Nationale de la Pêche, potentially exposing the personal details of 1,600 members to similar fraud risks.
Even without compromising on any bank credentials or passwords, customer lists alone carry high risks. Criminals can use that information to identify people who may keep expensive assets at home.
Also, scammers can leverage this information in launching their phishing attacks. They could also use it for text message fraud, phone call fraud, or even in-person visits. Identity theft attempts and scams using order information are also possible threats.
Social engineering attacks pose a particular danger in this case. Criminals could pose as representatives from Gold and Silver Purchase, a bank, or a compliance service. The detailed order histories give scammers the information they need to create convincing scenarios.
The gold investment sector has historically attracted cybercriminal attention. A 2O16 warning from Gold and Silver Purchase itself noted hackers targeted gold sales sites through intrusion attempts, phishing, and identity theft. The firm encouraged customers to verify the source of emails and not click suspicious links.
Security professionals have, for many years now, been pointing out that criminal organizations frequently mix stolen information. They collate data from one attack and merge it with information from other leaks and even social media.
This is something experts call social engineering. It revolves around manipulating trust rather than technical break-ins.
Investigation Underway
French authorities are continuing to investigate how the scammers identified the retired couple. They’re also looking into whether there are other victims of similar attacks.
The case also raises broader questions for companies that serve investors in physical assets. Even limited exposure of customer information can increase the risk of targeted fraud if criminals believe they have identified people with valuable holdings.
To consumers, the event points to one fact. Reputable firms and security services do not usually ask customers to deposit their money, gold, jewelry, or other valuables for safekeeping.
If someone calls or visits you citing a recent cyberattack or data breach, experts advise that you first confirm the claim independently through the firm.
As cyberattacks are evolving, con artists use a combination of stolen data and deception. They turn the fear of data breaches into a tool to steal from victims.