Lee Valley Tools Ltd.
ent_019dea4a8d5b62270e5f806ba1cacfc3
Disclosures
12
State AG · 12 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
57,708
nationwide · State AG TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Lee Valley Tools Ltd.
- Normalized
- lee valley tools-ca— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300AXBWX4OUWPO433
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- leevalley.com
Disclosure history (12)newest first
- Texas State AGas victim2025-06-06
Lee Valley Tools, Ltd. based in Reno, Nevada, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-03-12 and reported on 2025-06-06. 2,656 Texas residents were affected. 57,708 individuals affected in total. Types of information involved: Name of individual;Financial Information (e.g. account number, credit or debit card number). Consumers were notified via U.S. Mail.
- Nebraska State AGas victim2025-04-15
Lee Valley Tools, Ltd. notified Nebraska AG of a breach affecting customer data from Oct 8, 2024, to Mar 12, 2025. Unauthorized parties captured credit card info (number, expiry, CVV) and PII (name, address) via a cloud server. Lee Valley engaged experts, notified law enforcement, and offers 12 months of credit monitoring. ~435 RI residents affected; total count not specified.
- Vermont State AGas victim2025-04-15
Lee Valley Tools, Ltd. notified consumers of a data breach affecting approximately 435 Vermont residents (nationwide count undisclosed). Unauthorized access to a cloud server between Oct 8, 2024, and Mar 12, 2025, exposed names, addresses, and credit card details (number, expiration, CVV). The company engaged cybersecurity experts, notified law enforcement, and offered 12 months of credit monitoring.
- Indiana State AGas victim2025-04-15
Lee Valley Tools Ltd reported a data breach to the Indiana Attorney General. The breach occurred on 2024-10-08 and was reported on 2025-04-15. 1,022 Indiana residents were affected. 57,707 individuals affected in total.
- Oregon State AGas victim2025-04-09
Lee Valley Tools reported a data breach to the Oregon Attorney General. The breach was reported on 2025-04-09. The breach occurred during 10/8/2024 - 3/12/2025. The breach was discovered on 3/12/2025. 57,707 individuals were affected. Notice was sent on 4/9/2025.
- California State AGas victim2025-04-09
Lee Valley Tools, Ltd. disclosed that an unauthorized third party captured credit card information (number, expiration date, CVV) and personal data (name, address) from its website between October 8, 2024, and March 12, 2025. The company became aware of suspicious activity on March 12, 2025. The incident affected customers, including approximately 435 Rhode Island residents. The company engaged cybersecurity experts, notified law enforcement, and is offering 12 months of credit monitoring and identity restoration services.
- Washington State AGas victim2025-04-09
Lee Valley Tools, Ltd. reported unauthorized access to a cloud server supporting its website between October 8, 2024, and March 12, 2025. The incident exposed customer names, addresses, credit card numbers, expiration dates, and CVV codes. The company engaged cybersecurity experts, notified law enforcement, and offered 12 months of credit monitoring to affected individuals.
- New Hampshire State AGas victim2025-04-09
Lee Valley Tools, Ltd. reported a cybersecurity event affecting 774 New Hampshire residents. Unauthorized access occurred between October 8, 2024, and March 12, 2025, via a vulnerability in Sitecore CMS that allowed an attacker to inject code capturing payment card data at checkout. Lee Valley detected the incident on March 12, 2025, engaged forensic experts, notified law enforcement, and is offering credit monitoring services.
- Maine State AGas victim2025-04-09
Lee Valley Tools, Ltd. reported an external system breach (hacking) affecting 57,707 individuals, including 936 Maine residents. Unauthorized access occurred between October 8, 2024, and March 12, 2025. Compromised data included names, addresses, and credit card details (number, expiration, CVV). Notices were sent on April 15, 2025, offering 12 months of credit monitoring.
- Montana State AGas victim2025-04-09
Lee Valley Tools, Ltd. notified customers of unauthorized access to a cloud server supporting its website between October 8, 2024, and March 12, 2025. The attacker captured names, addresses, and credit card details (including CVV) via input capture. Lee Valley engaged cybersecurity experts and law enforcement, and is offering 12 months of credit monitoring. Approximately 435 Rhode Island residents are impacted.
- Iowa State AGas victim2025-04-09
Lee Valley Tools, Ltd. notified the Iowa AG of a cybersecurity event where an unauthorized third party exploited a vulnerability in Sitecore CMS to inject malicious code into the website checkout page. The code captured customer payment card data (name, address, card number, expiration, CVV) from transactions between October 8, 2024, and March 12, 2025. The incident affected 583 Iowa residents. Lee Valley engaged cybersecurity experts, notified law enforcement, removed the code, and is offering credit monitoring.
- Massachusetts State AGas victim2025-04-09
Lee Valley Tools, Ltd. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-04-09. 2,436 Massachusetts residents were affected.