TIFFANY AND COMPANY
bd_ef25a0a9294a271f · schema v1 · pii pii-v2
Full breach record for TIFFANY AND COMPANY →3 incidents on fileTiffany and Company notified Nebraska AG of a cybersecurity incident occurring on or around May 12, 2025. Unauthorized access was gained to systems containing client names, addresses, emails, phone numbers, sales data, and gift card numbers/PINs. The company engaged external cybersecurity experts and law enforcement. No evidence of harm was found as of September 9, 2025.
J jump to incidentP pin to compareR raw source
Incident timeline
May 12, 2025
Begins
May 12, 2025
Discovered
Sep 16, 2025
Filed
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- Montana State AGbd_09bad66e2b8c1ca42025-09-16Candidate
- Indiana State AGbd_d1a29158faec76b32025-09-16Verified
- Vermont State AGbd_e19e0f25f58441822025-09-16Verified
- Massachusetts State AGbd_58634fcfca97ce8a2025-09-17 · +1dVerified
Show 2 more filings ↓Show fewer ↑up to 3d gap
- Maine State AGbd_cb857f15207092f72025-09-17 · +1dVerified
- New Hampshire State AGbd_a6db0f367e8e0b382025-09-19 · +3dVerified
Filing propagation · 7 filings · 7 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.