Norwex USA, Inc.
ent_29acc61e3fb24d2902402d7f
Disclosures
11
State AG · 11 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
10,656
as filed · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Norwex USA, Inc.
- Normalized
- norwex usa— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- norwex.com
Disclosure history (11)newest first
- Rhode Island State AGas victim2025-01-03
Norwex USA, Inc. notified the Rhode Island Attorney General on December 23, 2024, of a security incident discovered on December 15, 2024, involving unauthorized access to systems around December 11, 2024. The breach may have exposed personal data including SSNs, driver's licenses, and payroll information. The number of affected individuals is unknown. Norwex engaged outside experts, reported to law enforcement, disabled system features, and is providing 24 months of identity monitoring services.
- Massachusetts State AGas victim2024-12-23
Norwex USA, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-12-23. 1 Massachusetts residents were affected.
- South Carolina State AGas victim2024-12-23
Norwex USA, Inc. disclosed a security breach discovered on Dec 15, 2024, involving unauthorized access to systems containing employee and customer PII (SSN, driver's license, payroll). Incident occurred around Dec 11, 2024. Company engaged forensic experts, notified law enforcement, and offered 2 years of identity monitoring.
- Montana State AGas victim2024-12-23
Norwex USA, Inc. disclosed a data breach occurring around December 11, 2024, discovered on December 15, 2024. Unauthorized access to systems containing employee and customer PII (SSN, driver's license, payroll, DOB, addresses) was detected. The company engaged forensic experts, notified law enforcement, enhanced security protocols, and offered two years of identity monitoring via Identity Defense.
- Delaware State AGas victim2024-12-23
Norwex USA, Inc. disclosed a security breach occurring around December 11, 2024, discovered on December 15, 2024. An unauthorized person accessed systems containing personal data, including SSNs, driver's licenses, payroll, and tax forms. Norwex activated incident response protocols, engaged outside experts, notified law enforcement, and restricted system access. Affected individuals were offered two years of complimentary identity monitoring through Identity Defense. The notification covers US residents, with specific instructions for Massachusetts.
- Oregon State AGas victim2024-12-23
Norwex USA, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2024-12-23. The breach occurred during 12/11/2024. The breach was discovered on 12/15/2024. Notice was sent on 12/23/2024.
- Vermont State AGas victim2024-12-23
Norwex USA, Inc. disclosed a data breach occurring around December 11, 2024, discovered on December 15, 2024. Unauthorized access to systems containing personal data (SSNs, driver's licenses, payroll, DOB, addresses) was identified. The company engaged outside experts, notified law enforcement, restricted access, and enhanced security protocols. Identity monitoring services were offered to affected individuals.
- Indiana State AGas victim2024-12-23
Norwex USA Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2024-12-11 and was reported on 2024-12-23. 10,656 Indiana residents were affected.
- Maine State AGas victim2024-12-23
Norwex USA, Inc. reported an external system breach (hacking) occurring on Dec 11, 2024, discovered on Dec 15, 2024. One Maine resident was affected. Compromised data included SSNs, driver's licenses, payroll info, and DOBs. Norwex engaged outside experts, notified law enforcement, restricted access, and offered 24-month identity monitoring.
- California State AGas victim2024-12-23
Norwex USA, Inc. notified the California Attorney General of a security breach discovered on December 15, 2024, involving unauthorized access to systems around December 11, 2024. The incident potentially exposed employee personal data including Social Security numbers, driver's licenses, payroll information, and tax forms. The company contained the incident, engaged outside experts, and offered two years of identity monitoring.
- Illinois State AGas victim2024-12-01
NORWEX USA, INC. filed a data-breach notice with the Illinois Attorney General in December 2024 (case 24-12-043). The register records the breach as discovered on December 11, 2024. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.