Beverages & More, Inc.
ent_019e6284c6d2b48356f71600e352c4a3
Disclosures
4
State AG · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
33
as filed · State AG MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Beverages & More, Inc.
- Normalized
- beverages more— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300WVXB1BG5U3Z655
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- Massachusetts State AGas victim2018-12-20
Beverages & More Inc reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-12-20. 33 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2018-12-18
Beverages & More, Inc. (BevMo) notified the NH AG of a data incident involving 3 NH residents. An unauthorized individual accessed the BevMo website (www.bevmo.com) between Aug 2 and Sep 26, 2018, installing malicious code to capture payment card info (card numbers, CVV2, billing/shipping addresses). NCR Corporation, the ecommerce vendor, detected and removed the script. BevMo engaged forensic experts and notified law enforcement.
- Montana State AGas victim2018-12-17
Beverages & More, Inc. (BevMo) notified customers of a data incident involving its ecommerce website operated by NCR Corporation. Unauthorized access occurred between August 2 and September 26, 2018, allowing installation of malicious code on the checkout page. Captured data included names, payment card numbers, CVV2, and addresses. BevMo engaged forensic investigators and contacted law enforcement.
- California State AGas victim2018-12-14
Beverages & More, Inc. (dba BevMo!) experienced a data breach affecting customer payment information. An unauthorized individual installed malicious code on the BevMo website checkout page via the ecommerce service provider, NCR Corporation. The incident occurred between August 2, 2018, and September 26, 2018. Affected data includes names, credit/debit card numbers, expiration dates, CVV2 codes, billing/shipping addresses, and phone numbers. The malicious code was removed, and forensic investigations were conducted.