Carl's Golfland, Inc.
ent_019e627ef80752ee38dbd1918b3c9cdb
Disclosures
4
State AG · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
651
as filed · State AG MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Carl's Golfland, Inc.
- Normalized
- carl s golfland— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 254900FMKEEKAQTV3Q70
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- Massachusetts State AGas victim2019-09-03
Carl's Golfland reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-09-03. 651 Massachusetts residents were affected. The report records the breach type as paper.
- Montana State AGas victim2019-08-30
Carl's Golfland, Inc. notified customers of a breach of its online shopping website. Unauthorized access occurred between March 25 and July 14, 2019, resulting in the exfiltration of credit card data (number, expiration, CVV) and customer PII (names, addresses, emails, phone numbers). The breach was discovered in late June 2019 via a bank inquiry. The company engaged in a forensic audit and cooperated with the Secret Service.
- California State AGas victim2019-08-30
Carl's Golfland, Inc. experienced a breach of its online shopping website between March 25 and July 14, 2019. The incident was discovered in late June 2019 via a bank inquiry. Unauthorized access resulted in the exfiltration of customer credit card numbers, expiration dates, CVVs, names, addresses, shipping info, emails, and phone numbers. The company notified the US Secret Service and conducted a forensic audit. Credit monitoring is offered to affected customers.
- New Hampshire State AGas victim2019-08-28
Carl’s Golfland, Inc. notified New Hampshire of a data breach affecting 113 state residents. Unauthorized access to the online shopping website occurred between March 25 and July 14, 2019, exposing customer names, addresses, emails, phone numbers, and full credit card details (number, expiration, CVV). Discovery was triggered by a bank inquiry in late June 2019. Notices were sent on August 29, 2019.