TIFFANY & CO.
ent_019fb6d2ca7fef29bfb338b47fb1f27a
Disclosures
3
State AG · 2 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
124
as filed · State AG MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- TIFFANY & CO.
- Normalized
- tiffany— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300EJG9IEYQL5XT21
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (3)newest first
- Massachusetts State AGas victim2017-08-04
Tiffany & Co. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-08-04. 2 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2012-09-10
Tiffany & Co. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2012-09-10. 124 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2012-09-05
Tiffany & Co. notified the NH Attorney General on Sept 5, 2012 that JPMorgan Chase Bank, N.A. experienced unauthorized access to servers containing employee PII (names, SSNs, banking info) from a travel expense system. ~3 NH residents affected. Chase contained access and enhanced security; Tiffany offered credit monitoring.
Subsidiary disclosures (9)filed by group companies
◈ These filings were made by or about subsidiaries of TIFFANY & CO. — not by TIFFANY & CO. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- New Hampshire State AGvia TIFFANY AND COMPANY2025-09-19
Tiffany and Company notified the NH Attorney General of a cybersecurity incident where an unauthorized third party gained access to company systems on May 12, 2025. The breach affected approximately 4 New Hampshire residents. Compromised data included names, addresses, phone numbers, emails, sales data, and gift card numbers/PINs. Tiffany disabled accounts, reset passwords, took systems offline, and engaged external cybersecurity experts. No evidence of further misuse was found.
- Massachusetts State AGvia TIFFANY AND COMPANY2025-09-17
Tiffany and Company reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-09-17. 63 Massachusetts residents were affected.
- Maine State AGvia TIFFANY AND COMPANY2025-09-17
Tiffany and Company experienced an external system breach (hacking) between May 12 and May 15, 2025. The incident compromised client names, addresses, emails, phone numbers, sales data, and gift card numbers/PINs. 2,590 individuals were affected, including 5 in Maine. The breach was discovered on September 9, 2025, and notifications were sent on September 16, 2025.
- Montana State AGvia TIFFANY AND COMPANY2025-09-16
Tiffany and Company notified Montana residents of a cybersecurity incident occurring on May 12, 2025, involving unauthorized access to systems. The breach compromised gift card numbers, PINs, and client PII (name, address, email, phone). The company engaged external cybersecurity experts and law enforcement. No evidence of harm was found at the time of notification.
- Indiana State AGvia TIFFANY AND COMPANY2025-09-16
Tiffany and Company reported a data breach to the Indiana Attorney General. The breach occurred on 2025-05-12 and was reported on 2025-09-16. 17 Indiana residents were affected. 2,590 individuals affected in total.
- Vermont State AGvia TIFFANY AND COMPANY2025-09-16
Tiffany and Company notified consumers of a cybersecurity incident on or around May 12, 2025, involving unauthorized access to systems containing gift card data. Affected information included names, addresses, emails, phone numbers, sales data, and gift card numbers/PINs. The company engaged external cybersecurity experts and coordinated with law enforcement. No evidence of further misuse was reported.
- Nebraska State AGvia TIFFANY AND COMPANY2025-09-16
Tiffany and Company notified Nebraska AG of a cybersecurity incident occurring on or around May 12, 2025. Unauthorized access was gained to systems containing client names, addresses, emails, phone numbers, sales data, and gift card numbers/PINs. The company engaged external cybersecurity experts and law enforcement. No evidence of harm was found as of September 9, 2025.
- Nebraska State AGvia TIFFANY AND COMPANY2025-07-04
Tiffany and Company notified Nebraska AG of a cybersecurity incident occurring on May 12, 2025, discovered on June 3, 2025. Unauthorized access resulted in the exfiltration of employee directory data, including names, contact info, and hashed/clear-text passwords. Tiffany disabled accounts, reset passwords, took systems offline, and engaged external experts. No specific count of affected individuals was provided.
- New Hampshire State AGvia TIFFANY AND COMPANY2012-03-21
Tiffany & Co. notified the NH Attorney General that UPS misdirected a package containing one NH resident's credit card application (including SSN) to Drugstore.com on March 15, 2012. The package was returned the same day. Tiffany sent notification on March 21, 2012, and offered one year of free credit monitoring.