HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
TIFFANY AND COMPANY
bd_e19e0f25f5844182 · schema v1 · pii pii-v1
Full breach record for TIFFANY AND COMPANY →Tiffany and Company notified consumers of a cybersecurity incident occurring on May 12, 2025, involving unauthorized access to systems containing gift card data, client names, addresses, and contact info. The company engaged external experts and law enforcement. No evidence of harm was found. No specific affected individual count was disclosed.
Vermont clock✗ VT AG >45 bday18 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_09bad66e2b8c1ca4Montana State AGfiled 2025-09-16Candidate
- bd_d1a29158faec76b3Indiana State AGfiled 2025-09-16Verified
- bd_cb857f15207092f7Maine State AGfiled 2025-09-17(1d gap)Verified
- bd_a6db0f367e8e0b38New Hampshire State AGfiled 2025-09-19(3d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-09-16-tiffany-and-company-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 16, 2025
- Raw hash
- 2423e2a255caaf02f1b62b212f14fedb81d43c0f54e95b7a06a3a0aad1dc4fbc
Reporting entity
- Name
- TIFFANY AND COMPANYnorm: tiffany and
- Domain
- tiffany.com
Victim entity
- Name
- TIFFANY AND COMPANYnorm: tiffany and
- Domain
- tiffany.com
Incident
- Discovered
- May 12, 2025
- Materiality determined
- Sep 9, 2025
- Notification sent
- Sep 16, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- coordinated with law enforcement authorities
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 18 weeks(127 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.