PAX Labs, Inc.
ent_019e629ce7cf4dbadc0d2559ae3af17f
Disclosures
4
State AG · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
6,000
nationwide · State AG CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- PAX Labs, Inc.
- Normalized
- pax labs— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300FKJA0AEKUHVG68
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- California State AGas victim2016-08-12
PAX Labs, Inc. disclosed a data breach affecting approximately 6,000 customers of its e-commerce sites PAXvapor.com and JUULvapor.com. Unauthorized parties accessed a cloud-based server between June 25 and July 22, 2016, installing malware to capture payment card data including cardholder names, addresses, card numbers, expiration dates, and CVV codes. The incident was discovered on July 15, 2016. PAX removed the malware, engaged forensic investigators, and implemented enhanced firewall rules and monitoring. Affected individuals were offered 12 months of identity protection.
- Montana State AGas victim2016-08-12
PAX Labs, Inc. notified customers of a data breach affecting approximately 6,000 individuals. Unauthorized parties gained access to cloud-based servers for PAXvapor.com and JUULvapor.com between June 25 and July 22, 2016, installing unauthorized software to steal payment card data including CVV codes. PAX detected the incident on July 15, 2016, removed the malware, engaged forensic investigators, and implemented enhanced firewall and monitoring controls. Affected individuals were offered 12 months of identity protection services.
- New Hampshire State AGas victim2016-08-11
PAX Labs, Inc. notified the New Hampshire Attorney General of a security incident where an unauthorized party gained access to a cloud-based website server between June 25 and July 22, 2016. The attacker installed unauthorized software to access payment card data (names, card numbers, CVV) of approximately 24 New Hampshire residents. PAX engaged forensic investigators, notified processors and law enforcement, and implemented enhanced firewall and monitoring rules. Affected residents were offered 12 months of credit monitoring and identity theft insurance.
- Massachusetts State AGas victim2016-08-11
PAX Labs, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-08-11. 229 Massachusetts residents were affected. The report records the breach type as electronic.