CLAIRE'S STORES, INC.
ent_019e5aa8136d6574a42a07cd8ae156fa
Disclosures
10
State AG · 8 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
60,842
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CLAIRE'S STORES, INC.
- Normalized
- claire s stores— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300N5HNYXI6JY7625
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (10)newest first
- Montana State AGas victim2020-07-08
Claire’s Stores, Inc. notified customers of a payment card data breach affecting its e-commerce sites. Malicious code was added to the site between April 7 and June 12, 2020, capturing checkout data including names, addresses, and payment card details. The company engaged forensic investigators, notified law enforcement, and offered one year of Experian IdentityWorks.
- Indiana State AGas victim2020-07-08
Claire's Stores, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2020-04-07 and was reported on 2020-07-08. 1,257 Indiana residents were affected. 60,842 individuals affected in total.
- Washington State AGas victim2020-07-08
Claire's Stores, Inc. notified the Washington AG of a cyberattack on its e-commerce site. Unauthorized code added between April 7 and June 12, 2020, exfiltrated customer checkout data including names, addresses, payment card details, and account passwords. 1,166 Washington residents were notified. Claire's engaged forensic investigators, removed the code, and notified law enforcement.
- Massachusetts State AGas victim2020-07-08
Claire's Stores, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-07-08. 1,656 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2020-07-08
Claire's Stores, Inc. identified malicious code on its e-commerce websites that captured payment card and contact information during checkout. The code was present intermittently between April 7, 2020, and June 12, 2020, when it was discovered and removed. The incident affected online customers; retail store purchases were not involved. Affected data includes names, addresses, phone numbers, payment card numbers, expiration dates, and CVVs. The company engaged a security firm, reinforced site security, notified law enforcement and payment card networks, and offered one year of Experian IdentityWorks to affected individuals.
- New Hampshire State AGas victim2020-07-08
Claire's Stores, Inc. notified the NH Attorney General of a security incident affecting 259 NH residents. Unauthorized code was added to the e-commerce site between April 7 and June 12, 2020, capturing checkout data including payment card details and PII. Claire's removed the code, engaged forensic investigators, notified law enforcement and the payment network, and offered credit monitoring.
- Oregon State AGas victim2020-07-08
Claire's Stores, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2020-07-08. The breach occurred during 4/7/2020 - 6/12/2020. The breach was discovered on 6/12/2020. 60,842 individuals were affected. Notice was sent on 7/8/2020.
- Illinois State AGas victim2020-01-01
CLAIRE'S STORES INC filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-251). The register records the breach as discovered on June 11, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Massachusetts State AGas victim2012-04-30
Claire's Stores reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2012-04-30. 513 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2012-04-26
Claire's Stores filed a breach notification with the New Hampshire Attorney General's office on April 26, 2012. The notification form indicates that Social Security numbers and dates of birth were compromised. The filing appears to be a standard state-AG template rather than a detailed incident report.