Sears Holdings Corporation
ent_019e5b5ae5837c47c7fdccafca314b8f
Disclosures
7
State AG · 7 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
3,021
as filed · State AG MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Sears Holdings Corporation
- Normalized
- sears holdings— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300KWWR4P1RYUVG65
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- South Carolina State AGas victim2018-05-18
Sears Holdings notified South Carolina AG that a third-party vendor incorporating a malicious script into Sears.com/Kmart.com code collected names, addresses, and payment card info from customers who placed online orders between Sept 27 and Oct 12, 2017. Vendor notified Sears in mid-March 2018. Sears notified card companies, investigated, and cooperated with law enforcement.
- Oregon State AGas victim2018-05-17
Sears Holdings Managment Corporation reported a data breach to the Oregon Attorney General. The breach was reported on 2018-05-17. The breach occurred during 9/27/2017 - 10/12/2017. The breach was discovered on 3/26/2018. Notice was sent on 5/7/2018.
- California State AGas victim2018-05-17
Sears Holdings Management Corporation notified customers that a vendor providing online support services for Sears.com and Kmart.com experienced a security incident. An unauthorized individual incorporated a malicious script into the vendor's code, collecting personal information (name, address) and payment card information from customers who completed online orders between September 27, 2017, and October 12, 2017. Sears was informed of the incident in mid-March 2018. Payment card companies were notified, and an investigation was conducted. No evidence suggests Sears' internal systems were accessed.
- Massachusetts State AGas victim2018-05-08
Sears Holdings Management Corporation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-05-08. 3,021 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2018-04-25
Sears Holdings notified Montana AG of a third-party vendor incident where a malicious script collected customer names, addresses, and payment card info from Sears.com and Kmart.com. Occurred Sept 27-Oct 12, 2017; discovered mid-March 2018. No specific count disclosed.
- Washington State AGas victim2018-04-24
Sears Holdings notified Washington AG of a breach affecting 2,373 residents. A third-party vendor's malicious script collected names, addresses, and payment card info from customers who ordered between Sept 27 and Oct 12, 2017. Discovered March 26, 2018. Notifications sent April 25, 2018.
- New Hampshire State AGas victim2018-04-24
Sears Holdings notified NH AG of a breach affecting 656 NH residents. A vendor's code was compromised with a malicious script collecting names, addresses, and payment card info from customers ordering between Sept 27 and Oct 12, 2017. Discovered March 26, 2018. Notifications sent April 25, 2018.