ORDER EXPRESS, INC.
ent_019e5981db3fa32012686f79c5a6fcf3
Disclosures
5
State AG · 5 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
63,220
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- ORDER EXPRESS, INC.
- Normalized
- order express— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 2549000XJGZMZ5IGJQ40
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- 🐻California State AGas victim2022-12-15
Order Express, Inc. disclosed a data breach affecting California and other state residents. Unauthorized access occurred between July 29, 2022, and September 7, 2022. The company engaged third-party specialists to investigate and secure its network. Affected data included names combined with government identifiers. Order Express offered 12-24 months of complimentary credit monitoring and identity protection services to impacted individuals.
- 🦬Montana State AGas victim2022-12-15
Order Express, Inc. reported a data breach to the Montana Attorney General. The breach was reported on 2022-12-15. The breach occurred from 7/29/2022 to 9/7/2022. 1 Montana residents were affected.
- 🦞Maine State AGas victim2022-12-15
Order Express, Inc., a financial services provider based in Chicago, IL, experienced an external system breach (hacking) on July 29, 2022. The incident compromised the names and driver's license numbers of 63,220 individuals, including 5 Maine residents. The breach was discovered on November 18, 2022. Order Express notified affected consumers in writing on December 15, 2022, and offered 12 months of credit monitoring services.
- ⛰️New Hampshire State AGas victim2022-12-15
Order Express, Inc. reported a ransomware attack discovered on September 7, 2022, involving unauthorized network access between July 29 and September 7, 2022. The incident impacted 3 New Hampshire residents, exposing names, driver's license numbers, and SSNs/TINs/ EINs. Order Express engaged third-party specialists, reset passwords, deployed EDR, and offered 12 months of credit monitoring.
- 🌲Washington State AGas victim2022-12-15
Order Express, Inc., a finance sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2022-09-07 and filed notice on 2022-12-15. 1,168 Washington residents were affected. 99 days elapsed between awareness and notification. 40 days to identify the breach. 0 days to contain the breach.