TIFFANY AND COMPANY
ent_019dea420e801cab23d647fd55dca657
Disclosures
9
State AG · 7 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
2,590
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- TIFFANY AND COMPANY
- Normalized
- tiffany and— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300C9X2TIB0FMTR23
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- tiffany.com
- Corporate parent
- TIFFANY & CO.— per GLEIF relationship records
Disclosure history (9)newest first
- New Hampshire State AGas victim2025-09-19
Tiffany and Company notified the NH Attorney General of a cybersecurity incident where an unauthorized third party gained access to company systems on May 12, 2025. The breach affected approximately 4 New Hampshire residents. Compromised data included names, addresses, phone numbers, emails, sales data, and gift card numbers/PINs. Tiffany disabled accounts, reset passwords, took systems offline, and engaged external cybersecurity experts. No evidence of further misuse was found.
- Massachusetts State AGas victim2025-09-17
Tiffany and Company reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-09-17. 63 Massachusetts residents were affected.
- Maine State AGas victim2025-09-17
Tiffany and Company experienced an external system breach (hacking) between May 12 and May 15, 2025. The incident compromised client names, addresses, emails, phone numbers, sales data, and gift card numbers/PINs. 2,590 individuals were affected, including 5 in Maine. The breach was discovered on September 9, 2025, and notifications were sent on September 16, 2025.
- Montana State AGas victim2025-09-16
Tiffany and Company notified Montana residents of a cybersecurity incident occurring on May 12, 2025, involving unauthorized access to systems. The breach compromised gift card numbers, PINs, and client PII (name, address, email, phone). The company engaged external cybersecurity experts and law enforcement. No evidence of harm was found at the time of notification.
- Indiana State AGas victim2025-09-16
Tiffany and Company reported a data breach to the Indiana Attorney General. The breach occurred on 2025-05-12 and was reported on 2025-09-16. 17 Indiana residents were affected. 2,590 individuals affected in total.
- Vermont State AGas victim2025-09-16
Tiffany and Company notified consumers of a cybersecurity incident on or around May 12, 2025, involving unauthorized access to systems containing gift card data. Affected information included names, addresses, emails, phone numbers, sales data, and gift card numbers/PINs. The company engaged external cybersecurity experts and coordinated with law enforcement. No evidence of further misuse was reported.
- Nebraska State AGas victim2025-09-16
Tiffany and Company notified Nebraska AG of a cybersecurity incident occurring on or around May 12, 2025. Unauthorized access was gained to systems containing client names, addresses, emails, phone numbers, sales data, and gift card numbers/PINs. The company engaged external cybersecurity experts and law enforcement. No evidence of harm was found as of September 9, 2025.
- Nebraska State AGas victim2025-07-04
Tiffany and Company notified Nebraska AG of a cybersecurity incident occurring on May 12, 2025, discovered on June 3, 2025. Unauthorized access resulted in the exfiltration of employee directory data, including names, contact info, and hashed/clear-text passwords. Tiffany disabled accounts, reset passwords, took systems offline, and engaged external experts. No specific count of affected individuals was provided.
- New Hampshire State AGas victim2012-03-21
Tiffany & Co. notified the NH Attorney General that UPS misdirected a package containing one NH resident's credit card application (including SSN) to Drugstore.com on March 15, 2012. The package was returned the same day. Tiffany sent notification on March 21, 2012, and offered one year of free credit monitoring.