HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICLowContained
The LoveSac Company
bd_8f82ad1bad5501b1 · schema v1 · pii pii-v1
Full breach record for The LoveSac Company →The LoveSac Company notified consumers of a cybersecurity incident occurring between Feb 12 and Mar 3, 2025. An unauthorized actor accessed systems and copied files containing names and other personal information. The company offered 24 months of credit monitoring via Experian. Rhode Island residents were specifically noted as impacted.
Vermont clock✗ VT AG >45 bday27 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
A leak claim by ransomhub about this victim predates this filing by 188 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_2ab4dbfe2f4645b5Indiana State AGfiled 2025-09-04Candidate
- bd_55ce6f94b7259130Indiana State AGfiled 2025-09-04Verified
- bd_5ab5de4fec271deeMaine State AGfiled 2025-09-04Candidate
- bd_81c14587331502c2Maine State AGfiled 2025-09-04Verified
Show 2 more filings ↓Show fewer ↑up to 1d gap
- bd_bedf34d850941636New Hampshire State AGfiled 2025-09-04Candidate
- bd_a32eb25ec7419355New Hampshire State AGfiled 2025-09-05(1d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-09-04-lovesac-company-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 4, 2025
- Raw hash
- f03e1e0d941a7370e2b7814b61b6027e46732dd114d74de1001f0e4df48e5fcc
Reporting entity
- Name
- The LoveSac Companynorm: the lovesac
- Domain
- lovesac.com
Victim entity
- Name
- The LoveSac Companynorm: the lovesac
- Domain
- lovesac.com
Incident
- Discovered
- Feb 28, 2025
- Materiality determined
- —
- Notification sent
- Sep 4, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Will notify applicable regulatory authorities, as required by law
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 27 weeks(188 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.