STEIN MART, INC.
ent_019e5a1de2d21100c4bc3a2e8d582e17
Disclosures
9
State AG · 7 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
1,208
as filed · State AG MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- STEIN MART, INC.
- Normalized
- stein mart— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5299003WK411DOKT6U67
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (9)newest first
- California State AGas victim2018-11-27
Stein Mart, Inc. experienced a data breach between December 28, 2017, and July 9, 2018, due to unauthorized code in a third-party vendor's web application used on steinmart.com. The incident potentially exposed cardholders' names, addresses, email addresses, credit account numbers, security codes, and expiration dates. Synchrony Bank, the card issuer, notified affected customers, issued new cards, and offered credit monitoring. The unauthorized code and vendor login feature were removed.
- South Carolina State AGas victim2018-11-14
Stein Mart, Inc. notified customers of a third-party vendor incident involving Annex Cloud. Unauthorized code was present on the checkout process between Dec 28, 2017 and July 9, 2018, potentially capturing names, addresses, emails, and payment card details (including CVV). Stein Mart removed the code and the login feature while investigating. No specific count of affected individuals was provided.
- New Hampshire State AGas victim2018-11-14
Stein Mart, Inc. notified the NH AG of a third-party vendor breach involving Annex Cloud. Unauthorized code inserted into Annex Cloud's login app could have captured customer PII and payment card data (including CVV) between Dec 28, 2017 and July 9, 2018. Stein Mart removed the app and notified 195 NH residents starting Nov 13, 2018.
- Montana State AGas victim2018-11-13
Stein Mart, Inc. notified customers that unauthorized code added by third-party vendor Annex Cloud to its login service may have captured checkout data (name, address, email, payment card info, CVV) during four periods in May-July 2018. Stein Mart removed the login feature and is investigating.
- California State AGas victim2018-11-13
Stein Mart, Inc. notified customers of a web skimmer incident involving their third-party vendor Annex Cloud. Unauthorized code was added to Annex Cloud's login integration on steinmart.com and could have captured checkout information including name, address, email, payment card number, expiration date, and CVV during multiple periods between December 28, 2017 and July 9, 2018.
- Washington State AGas victim2018-11-13
Stein Mart, Inc. notified the Washington AG of a third-party vendor breach involving Annex Cloud. Unauthorized code inserted into Annex Cloud's social login application could have captured customer checkout data (name, address, email, payment card info, CVV) between Dec 28, 2017 and Jul 9, 2018. Stein Mart removed the app and notified 680 Washington residents starting Nov 13, 2018.
- Oregon State AGas victim2018-11-13
Stein Mart, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2018-11-13. The breach occurred during 12/28/2017 - 12/28/2017. The breach was discovered on 10/25/2018. Notice was sent on 11/13/2018.
- Montana State AGas victim2018-09-09
Stein Mart, Inc. notified customers of a third-party vendor breach involving Annex Cloud. Unauthorized code was added to Annex Cloud's login service, capturing customer checkout data (name, address, email, payment card info, CVV) during four periods in May-July 2018. Stein Mart removed the feature and is investigating.
- Massachusetts State AGas victim2018-09-07
Stein Mart Inc reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-09-07. 1,208 Massachusetts residents were affected. The report records the breach type as electronic.
Supply-chain cascadesreviewed and confirmed
- STEIN MART, INC.’s filing is one of at least 4 in the Social Annex, Inc. supply-chain incident (2018).