HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
TIFFANY AND COMPANY
bd_a6db0f367e8e0b38 · schema v1 · pii pii-v1
Full breach record for TIFFANY AND COMPANY →Tiffany and Company notified the New Hampshire AG of unauthorized access to systems on May 12, 2025. The incident affected 4 NH residents, exposing names, contact info, sales data, and gift card numbers/PINs. Tiffany engaged external experts, reset credentials, and coordinated with law enforcement.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_cb857f15207092f7Maine State AGfiled 2025-09-17(2d gap)Verified
- bd_09bad66e2b8c1ca4Montana State AGfiled 2025-09-16(3d gap)Candidate
- bd_d1a29158faec76b3Indiana State AGfiled 2025-09-16(3d gap)Verified
- bd_e19e0f25f5844182Vermont State AGfiled 2025-09-16(3d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/tiffany-company-20250919.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 19, 2025
- Raw hash
- 68147439161f546fa106bdc8ac596ebc7851706b2167ba65085ba0e58cfdad28
Reporting entity
- Name
- TIFFANY AND COMPANYnorm: tiffany and
- Domain
- tiffany.com
Victim entity
- Name
- TIFFANY AND COMPANYnorm: tiffany and
- Domain
- tiffany.com
Incident
- Discovered
- May 12, 2025
- Materiality determined
- —
- Notification sent
- Sep 19, 2025
- Affected individuals
- 4
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 19 weeks(130 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.