TIFFANY AND COMPANY
bd_09bad66e2b8c1ca4 · schema v1 · pii pii-v1
Full breach record for TIFFANY AND COMPANY →3 incidents on fileTiffany and Company notified Montana residents of a cybersecurity incident occurring on May 12, 2025, involving unauthorized access to systems. The breach compromised gift card numbers, PINs, and client PII (name, address, email, phone). The company engaged external cybersecurity experts and law enforcement. No evidence of harm was found at the time of notification.
J jump to incidentP pin to compareR raw source
Incident timeline
May 12, 2025
Begins
May 12, 2025
Discovered
Sep 16, 2025
Filed
vs. sector median
+11 wks slower
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- Indiana State AGbd_d1a29158faec76b32025-09-16Verified
- Vermont State AGbd_e19e0f25f58441822025-09-16Verified
- Nebraska State AGbd_ef25a0a9294a271f2025-09-16Verified
- Massachusetts State AGbd_58634fcfca97ce8a2025-09-17 · +1dVerified
Show 2 more filings ↓Show fewer ↑up to 3d gap
- Maine State AGbd_cb857f15207092f72025-09-17 · +1dVerified
- New Hampshire State AGbd_a6db0f367e8e0b382025-09-19 · +3dVerified
Filing propagation · 7 filings · 7 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.