HackingStolen CredentialsCapture Stored DataData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Lands End, Inc.
bd_430bdf4543e5d258 · schema v1 · pii pii-v1
Full breach record for Lands End, Inc. →Lands’ End, Inc. notified Vermont consumers of a December 6, 2024, data security incident where an unauthorized third party accessed a portion of its corporate network. The breach impacted current and former employees and their dependents, exposing personal information including names, addresses, and government IDs. No evidence of fraud was found. Lands’ End engaged law enforcement and cybersecurity experts, reinforced security protocols, and provided 24 months of credit monitoring via Experian.
Vermont clock✗ VT AG >45 bday36 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_d581ec32b62a93aeNew Hampshire State AGfiled 2025-08-18Verified
- bd_0a96b1b385c0588bMaine State AGfiled 2025-08-13(5d gap)Candidate
- bd_6e27ca72a2a65c9eIndiana State AGfiled 2025-08-13(5d gap)Verified
- bd_f4909ac389fc6b90Montana State AGfiled 2025-08-13(5d gap)Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-08-18-lands-end-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 18, 2025
- Raw hash
- 85f6c4b371889b50802afddbc159e89f2eb7d76b8de8753582c4db112d70c70d
Reporting entity
- Name
- Lands End, Inc.norm: lands end
- Domain
- landsend.com
Victim entity
- Name
- Lands End, Inc.norm: lands end
- Domain
- landsend.com
Incident
- Discovered
- Dec 6, 2024
- Materiality determined
- —
- Notification sent
- Aug 13, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- investigate what happened with the assistance of law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 36 weeks(255 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.