Sugarfina USA, LLC
ent_41cbbd2989e72d2b589ba28a
Disclosures
9
State AG · 9 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
39,794
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Sugarfina USA, LLC
- Normalized
- sugarfina usa— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- sugarfina.com
Disclosure history (9)newest first
- New Hampshire State AGas victim2021-06-01
Sugarfina USA, LLC notified the NH AG of a cyber-attack affecting ~150 NH residents. Unauthorized actors may have accessed payment card info (name, address, CC#, exp, CVV, username/password) from orders placed Nov 2019–Sep 2020. Attack discovered Jan 2021; notification sent May 2021. Malicious code on website allowed access. Investigation ongoing.
- Maine State AGas victim2021-05-25
Sugarfina USA, LLC reported an external system breach occurring between November 1, 2019, and September 3, 2020. Discovered on January 15, 2021, the incident compromised names and financial account numbers (including credit/debit card numbers with security codes/PINs) for 39,794 individuals, including 73 Maine residents. Written notification was sent on May 25, 2021. No identity theft protection services were offered.
- Massachusetts State AGas victim2021-05-25
Sugarfina USA, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-05-25. 1,540 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2021-05-25
Sugarfina USA, LLC reported a cyber-attack involving malicious code on its website that may have allowed unauthorized access to customer payment card information (cardholder name, billing address, credit card number, expiration date, CVV, and potentially username/password) for orders placed between November 1, 2019, and September 3, 2020. The incident was discovered on January 15, 2021. Sugarfina secured its website and is notifying affected individuals and regulators.
- Oregon State AGas victim2021-05-25
Sugarfina USA, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2021-05-25. The breach occurred during 1/1/0001. The breach was discovered on 1/15/2021. 39,794 individuals were affected. Notice was sent on 5/25/2021.
- Indiana State AGas victim2021-05-25
Sugarfina USA, LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2019-11-01 and was reported on 2021-05-25. 270 Indiana residents were affected. 39,794 individuals affected in total.
- Montana State AGas victim2021-05-25
Sugarfina USA, LLC notified Montana regulators of a cyber-attack involving malicious code on its website that potentially exposed customer payment card information (names, billing addresses, card numbers, CVVs) and credentials. The unauthorized access window was November 1, 2019, to September 3, 2020. Sugarfina discovered the incident on January 15, 2021, secured the site, and launched an investigation.
- Washington State AGas victim2021-05-25
Sugarfina USA, LLC notified Washington AG of a cyberattack affecting 1,019 residents. Unauthorized actors may have accessed payment card info (name, address, card number, CVV, username/password) from orders placed Nov 2019–Sep 2020. Incident discovered Jan 2021; notification sent May 2021.
- Illinois State AGas victim2021-01-01
SUGARFINA USA, LLC filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-195). The register records the breach as discovered on January 15, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.