TIFFANY AND COMPANY
ent_019dea420e801cab23d647fd55dca657
Disclosures
5
State AG · 5 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
2,590
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- TIFFANY AND COMPANY
- Normalized
- tiffany and— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300C9X2TIB0FMTR23
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- tiffany.com
Disclosure history (5)newest first
- ⛰️New Hampshire State AGas victim2025-09-19
Tiffany and Company notified the New Hampshire AG of unauthorized access to systems on May 12, 2025. The incident affected 4 NH residents, exposing names, contact info, sales data, and gift card numbers/PINs. Tiffany engaged external experts, reset credentials, and coordinated with law enforcement.
- 🦞Maine State AGas victim2025-09-17
Tiffany and Company experienced unauthorized access to certain company systems on or around May 12–15, 2025. The breach was discovered on September 9, 2025. Affected data included client name, postal address, email address, phone number, sales data, internal client reference number, and Tiffany gift card number and PIN. 2,590 individuals were affected in total, including 5 Maine residents. No identity theft protection services were offered.
- 🦬Montana State AGas victim2025-09-16
Tiffany and Company reported a data breach to the Montana Attorney General. The breach was reported on 2025-09-16. The breach occurred on 05/12/2025. 3 Montana residents were affected.
- 🏎️Indiana State AGas victim2025-09-16
Tiffany and Company reported a data breach to the Indiana Attorney General. The breach occurred on 2025-05-12 and was reported on 2025-09-16. 17 Indiana residents were affected. 2,590 individuals affected in total.
- 🍁Vermont State AGas victim2025-09-16
Tiffany and Company notified consumers of a cybersecurity incident occurring on May 12, 2025, involving unauthorized access to systems containing gift card data, client names, addresses, and contact info. The company engaged external experts and law enforcement. No evidence of harm was found. No specific affected individual count was disclosed.