LÍLLÉbaby
ent_232cd7760ec9eb66056d6e36
Disclosures
5
State AG · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
37,000
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- LÍLLÉbaby
- Normalized
- lillebaby— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- lillebaby.com
Disclosure history (5)newest first
- Massachusetts State AGas victim2018-08-29
LILLEbaby reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-08-29. 883 Massachusetts residents were affected. The report records the breach type as electronic.
- Oregon State AGas victim2018-08-29
LÍLLÉbaby reported a data breach to the Oregon Attorney General. The breach was reported on 2018-08-29. The breach occurred during 6/1/2016 - 6/1/2016. The breach was discovered on 6/15/2018. 37,000 individuals were affected. Notice was sent on 8/28/2018.
- New Hampshire State AGas victim2018-08-29
LÍLLÉbaby notified the NH AG of a malware incident on its e-commerce platform affecting customer payment card data (names, numbers, expirations, CVVs) from June 2016 to July 2018. 177 NH residents affected. Notifications sent Aug 28, 2018. Forensics engaged, FBI notified, platform security enhanced.
- Washington State AGas victim2018-08-29
LILLEbaby notified Washington AG of a malware incident on its e-commerce platform affecting payment card data (names, numbers, CVVs) for customers from June 2016 to July 2018. 1,557 WA residents affected. Discovered June 2018. FBI and card brands notified. Forensics firm retained. Remediation included platform security upgrades and payment processor transition.
- California State AGas victim2018-08-29
LÍLLÉbaby reported a data security incident involving unauthorized malware installation on its e-commerce platform. The malware potentially compromised payment card information (names, card numbers, expiration dates, security codes) for customers who made purchases between June 2016 and July 9, 2018. The company discovered the incident in June 2018. 4,068 California residents were affected. LÍLLÉbaby engaged a forensics firm, removed the malware, reported to the FBI and payment card brands, and is rebuilding its web platform with enhanced security. Identity monitoring services were offered to affected individuals.