Vermont Christmas Company
ent_29879b8ef2dfed0eae108844
Disclosures
7
State AG · 7 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
12,533
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Vermont Christmas Company
- Normalized
- vermont christmas— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- vermontchristmasco.com
Disclosure history (7)newest first
- Vermont State AGas victim2023-08-09
Vermont Christmas Company notified consumers of a data breach involving its third-party e-commerce vendor, CommerceV3. Unauthorized access occurred between Nov 2021 and Dec 2022. Impacted data included names, billing addresses, emails, payment card numbers, CVVs, and expiration dates. CommerceV3 implemented additional security measures and notified law enforcement. Vermont Christmas Company is reviewing vendor procedures and notifying regulators.
- Massachusetts State AGas victim2023-08-09
Vermont Christmas Company reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-08-09. 704 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2023-08-09
Vermont Christmas Company notified customers of a third-party vendor (CommerceV3) breach involving unauthorized access to payment card data between Nov 2021 and Dec 2022. Impacted data included names, billing addresses, emails, card numbers, CVVs, and expiration dates. VCC is reviewing vendor procedures and notifying regulators.
- Indiana State AGas victim2023-08-09
Vermont Christmas Company reported a data breach to the Indiana Attorney General. The breach occurred on 2021-11-24 and was reported on 2023-08-09. 218 Indiana residents were affected. 12,533 individuals affected in total.
- California State AGas victim2023-08-09
Vermont Christmas Company notified customers of unauthorized access to its third-party vendor, CommerceV3, between Nov 24, 2021, and Dec 14, 2022. Potentially impacted data includes name, billing address, email, payment card number, CVV, and expiration date. The company is reviewing vendor procedures and notifying regulators.
- New Hampshire State AGas victim2023-08-09
Vermont Christmas Company notified New Hampshire AG of a third-party vendor breach involving CommerceV3. Unauthorized access to CommerceV3 systems occurred between Nov 24, 2021 and Dec 14, 2022. Cardholder information was potentially impacted. VCC is reviewing vendor policies and notifying regulators. No specific count of affected individuals was disclosed in this filing.
- Maine State AGas victim2023-08-09
Vermont Christmas Company reported a third-party vendor incident on 11/24/2021, discovered on 06/08/2023. 12,533 individuals were affected, including 152 Maine residents. The breach involved names and financial account/credit card numbers. Written notification was sent on 08/09/2023.
Supply-chain cascadesreviewed and confirmed
- Vermont Christmas Company’s filing is one of at least 31 in the CommerceV3 supply-chain incident (2023).