Polished.com
ent_6aeb9366e056c2353cddcb48
Disclosures
8
SEC 8-K · State AG · 8 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
9,290
nationwide · SEC 8-K FEDERAL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Polished.com
- Normalized
- polishedcom— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- polished.com
Disclosure history (8)newest first
- FEDERALSEC 8-Kas victim2023-05-26
Polished.com Inc. disclosed a hacking attack on its e-commerce checkout page on March 16, 2023. Personal information (names, addresses, zip codes) and payment card data (numbers, expiration dates, CVVs) was extracted from the Company's systems; out of an abundance of caution the Company notified approximately 9,290 individuals as of May 24, 2023. The company deployed containment measures, engaged third-party experts, and notified law enforcement. The matter is considered remediated.
- Maine State AGas victim2023-05-22
Polished.com, an e-commerce company, experienced an external system breach affecting 9,290 individuals. The incident occurred between March 16, 2023, and April 23, 2023, and was discovered on March 17, 2023. The compromised information includes names combined with financial account or credit/debit card numbers and their associated security codes or PINs. Affected residents were notified on May 22, 2023.
- Montana State AGas victim2023-05-22
Polished.com notified Montana residents of a security incident where an unauthorized party accessed payment card information (name, address, card number, CVV) via its website between March 16 and April 23, 2023. The incident was discovered on March 17, 2023. Polished engaged a cybersecurity firm and enhanced security protocols.
- Vermont State AGas victim2023-05-22
Polished.com notified consumers of a security incident where an unauthorized party accessed AppliancesConnection.com between March 16 and April 23, 2023. The attacker acquired payment card information including names, addresses, card numbers, expiration dates, and CVVs. Polished engaged a cybersecurity firm, enhanced security protocols, and established a call center. No specific count of affected individuals was disclosed.
- California State AGas victim2023-05-22
Polished.com (AppliancesConnection.com) reported that an unauthorized party gained access to its website between March 16 and April 23, 2023, acquiring payment card data (name, address, zip code, card number, expiration date, CVV) entered by customers during that period. The company engaged a cybersecurity firm, secured its systems, and enhanced security protocols. Notice sent May 22, 2023.
- Massachusetts State AGas victim2023-05-22
Polished.com reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-05-22. 261 Massachusetts residents were affected. The report records the breach type as electronic.
- Indiana State AGas victim2023-05-22
Polished.com reported a data breach to the Indiana Attorney General. The breach occurred on 2023-03-16 and was reported on 2023-05-22. 125 Indiana residents were affected. 9,290 individuals affected in total.
- New Hampshire State AGas victim2023-05-22
Polished.com notified the NH Attorney General of a cybersecurity incident where an unauthorized actor accessed its website, AppliancesConnection.com, between March 16 and April 23, 2023. The breach potentially exposed payment card information of 57 New Hampshire residents. Polished engaged a cybersecurity firm, mailed notifications, and is enhancing security protocols.