SelectBlinds
ent_0a6fb21b9b08d1651ae2a37c
Disclosures
14
State AG · 12 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
206,238
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- SelectBlinds
- Normalized
- selectblinds— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- selectblinds.com
Disclosure history (14)newest first
- Massachusetts State AGas victim2024-11-01
SelectBlinds reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-11-01. 5,530 Massachusetts residents were affected.
- Maine State AGas victim2024-10-31
SelectBlinds, an Arizona-based online retailer, experienced an external system breach (hacking) that began on January 7, 2024 and was discovered on September 28, 2024. The breach affected 206,238 individuals total, including 1,185 Maine residents. Consumer notifications were sent on October 31, 2024. No identity theft protection services were offered.
- Vermont State AGas victim2024-10-31
SelectBlinds notified consumers of a data breach where malware was embedded on its website starting Jan 7, 2024, allowing data scraping of checkout transactions. The incident was discovered on Sept 28, 2024. Compromised data included names, addresses, phone numbers, and payment card details (number, expiration, CVV). SelectBlinds contained the incident, removed malware, and locked user accounts.
- Delaware State AGas victim2024-10-31
SelectBlinds, an online retailer of custom window coverings, disclosed a data breach occurring on or about January 7, 2024, discovered on September 28, 2024. An unauthorized third party embedded malware on the SelectBlinds website to scrape sales transaction data from the checkout page. Affected data included names, emails, shipping/billing addresses, phone numbers, and payment card information (number, expiration, CVV). The incident was contained, malware eradicated, and notifications sent on October 31, 2024, to affected individuals, including 815 Rhode Island residents.
- Montana State AGas victim2024-10-31
SelectBlinds notified affected individuals of a data breach where malware embedded on its website allowed unauthorized scraping of checkout data starting Jan 7, 2024. The incident was discovered on Sep 28, 2024. Compromised data included names, addresses, phone numbers, and payment card details (including CVV). SelectBlinds engaged external experts, contained the incident, and locked user accounts.
- Indiana State AGas victim2024-10-31
SelectBlinds reported a data breach to the Indiana Attorney General. The breach occurred on 2024-01-07 and was reported on 2024-10-31. 2,140 Indiana residents were affected. 206,238 individuals affected in total.
- New Hampshire State AGas victim2024-10-31
SelectBlinds notified the NH AG and ~1,206 residents of a data security incident. Beginning Jan 7, 2024, malware was embedded on the checkout page to scrape transaction data. SelectBlinds detected unusual activity on Sep 28, 2024, and completed an investigation on Oct 10, 2024. Affected data includes personal and payment information. SelectBlinds locked user accounts, engaged forensic experts, and notified law enforcement.
- California State AGas victim2024-10-31
SelectBlinds, an online retailer of custom window coverings, experienced a data breach beginning on or about January 7, 2024. An unauthorized third party embedded malware on the SelectBlinds website, allowing data scraping of sales transactions entered on the checkout page. The company became aware of the incident on September 28, 2024. Affected data includes names, emails, shipping/billing addresses, phone numbers, payment card numbers, expiration dates, CVV codes, and potentially usernames/passwords. The incident was contained, malware eradicated, and user accounts temporarily locked. No specific count of affected individuals was disclosed in the provided notice samples.
- South Carolina State AGas victim2024-10-31
SelectBlinds notified South Carolina and other states of a data breach where malware embedded on its website scraped user login credentials from the checkout page starting Jan 7, 2024. The company discovered the incident on Sep 28, 2024, contained the threat, and locked affected accounts. Usernames and passwords were compromised.
- Oregon State AGas victim2024-10-31
SelectBlinds reported a data breach to the Oregon Attorney General. The breach was reported on 2024-10-31. The breach occurred during 1/7/2024 - 9/28/2024. The breach was discovered on 9/28/2024. 206,238 individuals were affected. Notice was sent on 10/31/2024.
- Washington State AGas victim2024-10-31
SelectBlinds, an online retailer, disclosed a data breach where an unauthorized third party embedded malware on its website starting January 7, 2024, allowing data scraping of checkout transactions. The incident was discovered on September 28, 2024. Compromised data included names, addresses, phone numbers, and payment card details (including CVV). 7,530 Washington residents were notified.
- Vermont State AGas victim2024-10-29
SelectBlinds notified consumers of a data breach where malware embedded on its website scraped transaction data from January 7, 2024, through September 28, 2024. Affected data included names, addresses, payment card details (including CVV), and credentials. SelectBlinds engaged external experts, contained the incident, and locked user accounts. No specific total affected count was disclosed in the filing.
- Delaware State AGas victim2024-10-07
SelectBlinds notified affected individuals of a data breach where malware was embedded on its website starting January 7, 2024, allowing unauthorized scraping of checkout data. The incident was discovered on September 28, 2024. Compromised data included names, addresses, phone numbers, and payment card details (including CVV). SelectBlinds contained the incident, engaged external experts, and locked user accounts.
- Illinois State AGas victim2024-10-01
SELECTBLINDS filed a data-breach notice with the Illinois Attorney General in October 2024 (case 24-10-074). The register records the breach as discovered on January 7, 2024. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.