LEM
ent_6ac9588e0744ea61118ae681
Disclosures
5
State AG · 5 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
29,394
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- LEM
- Normalized
- lem— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- lem.com
Disclosure history (5)newest first
- 🦫Oregon State AGas victim2023-07-20
LEM Products Direct LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2023-07-20. The breach occurred during 11/24/2021 - 12/14/2022. The breach was discovered on 6/6/2023. 29,394 individuals were affected. Notice was sent on 7/13/2023.
- 🦬Montana State AGas victim2023-07-13
LEM Products Direct LLC reported a data breach to the Montana Attorney General. The breach was reported on 2023-07-13. The breach occurred from 11/24/2021 to 12/14/2022. 412 Montana residents were affected.
- ⛰️New Hampshire State AGas victim2023-07-13
LEM Products Direct LLC notified New Hampshire AG of a third-party breach involving its e-commerce platform provider, CommerceV3. Unauthorized access to cardholder data occurred between Nov 24, 2021 and Dec 14, 2022. CommerceV3 discovered the potential access on May 3, 2023, after forensic investigation. LEM Products Direct LLC notified affected individuals on July 13, 2023.
- 🐻California State AGas victim2023-07-13
LEM Products Direct LLC notified customers that an unauthorized party accessed its third-party e-commerce platform, CommerceV3, between November 24, 2021, and December 14, 2022. The incident potentially exposed payment card information, including card numbers, expiration dates, and CVVs, along with names, email addresses, and billing addresses. CommerceV3 discovered the access on May 3, 2023, and notified LEM on June 6, 2023. LEM implemented additional security measures and advised customers to monitor their accounts.
- 🌲Washington State AGas victim2023-07-06
LEM Products Direct LLC, a business sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2023-06-06 and filed notice on 2023-07-06. 640 Washington residents were affected. 30 days elapsed between awareness and notification. 559 days to identify the breach. 0 days to contain the breach.