Loungefly LLC
ent_5947333c234b5b71bb293934
Disclosures
6
State AG · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
4,600
nationwide · State AG CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Loungefly LLC
- Normalized
- loungefly— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- loungefly.com
Disclosure history (6)newest first
- California State AGas victim2019-06-26
Loungefly, LLC notified customers of a potential data breach involving unauthorized code placed on its online store system between September 19, 2018, and February 13, 2019. Up to 4,600 customers may have had payment card data (account numbers, expiration dates, security codes) and account credentials (usernames, passwords) exposed. The company secured the network, removed the code, and is enhancing password requirements and security controls.
- New Hampshire State AGas victim2019-06-26
Loungefly, LLC filed a supplemental notice to the NH AG regarding a cybersecurity incident affecting online store customers. Unauthorized code was placed on the payment processing network between Sept 19, 2018 and Feb 13, 2019. The incident potentially impacted usernames, passwords, and payment card data for up to 4,600 individuals. 7 NH residents were identified in this supplemental update. The incident was discovered in April 2019.
- Massachusetts State AGas victim2019-04-30
Loungefly, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-04-30. 59 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2019-04-26
Loungefly, LLC notified consumers that unauthorized code was placed on its online store payment processing network between September 19 and December 17, 2018. The company removed the code and investigated, concluding that while it cannot confirm data theft, payment card information for less than 3,600 transactions may have been affected. The incident is contained.
- Montana State AGas victim2019-04-26
Loungefly, LLC notified Montana AG of a potential unauthorized access to its online store payment processing network. Unauthorized code was placed on the network between Sept 19 and Dec 17, 2018. Payment card data (names, account numbers, security codes) for up to 3,600 transactions may have been affected, though theft was not confirmed. Investigation concluded April 3, 2019. Law enforcement was notified.
- New Hampshire State AGas victim2019-04-26
Loungefly, LLC notified the NH AG of a potential unauthorized acquisition of payment card data. Unauthorized code was placed on the payment processing network. The incident affected transactions between Sept 19 and Dec 17, 2018. Up to 3,600 payment cards may be affected, including 8 NH residents. Data potentially exposed includes cardholder names, account numbers, expiration dates, and security codes. Investigation concluded April 3, 2019.