Newegg
ent_4eaea9855b443fa2a5d59844
Disclosures
7
State AG · 7 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
20,231
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Newegg
- Normalized
- newegg— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- newegg.com
Disclosure history (7)newest first
- South Carolina State AGas victim2018-11-19
Newegg, Inc. notified customers of unauthorized access to its website servers between August 13 and September 19, 2018. Attackers modified the checkout page to capture order information, including names, addresses, and full payment card details (number, expiration, CVV2). Newegg engaged a security firm, removed malicious code, and notified law enforcement and card networks. Investigation confirmed on October 15, 2018.
- New Hampshire State AGas victim2018-11-16
Newegg, Inc. notified the NH Attorney General of a security incident where unauthorized users modified the website checkout page to collect customer data (names, addresses, payment card numbers, CVV2) for orders placed between Aug 13 and Sep 19, 2018. 1,066 NH residents were affected. Newegg engaged forensic investigators, removed malicious code, and notified law enforcement.
- Washington State AGas victim2018-11-15
Newegg Inc. notified the Washington AG of a security incident where unauthorized users modified the website checkout page to collect customer data. The breach affected orders placed between August 13 and September 19, 2018, exposing names, addresses, and payment card details (including CVV2) for 5,931 Washington residents. Newegg engaged forensic investigators, removed malicious code, and notified law enforcement.
- Massachusetts State AGas victim2018-11-15
Newegg Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-11-15. 4,760 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2018-11-15
Newegg notified customers in Montana of a cybersecurity incident where unauthorized access to checkout servers between Aug 13 and Sep 19, 2018, potentially exposed order details, payment card numbers, and CVV2 codes. Newegg engaged forensic investigators, removed malicious code, and notified law enforcement.
- California State AGas victim2018-11-15
Newegg Inc. disclosed that an unauthorized user modified its website checkout page between August 13 and September 19, 2018, to collect customer order and payment card information, including names, addresses, card numbers, expiration dates, and CVV2 codes. The incident was discovered on September 18, 2018. Newegg removed the unauthorized code, secured servers, and notified law enforcement and payment card networks.
- Oregon State AGas victim2018-11-15
Newegg Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2018-11-15. The breach occurred during 8/13/2018 - 8/13/2018. The breach was discovered on 10/23/2018. 20,231 individuals were affected. Notice was sent on 9/19/201811/15/2018.