Polished.com
ent_6aeb9366e056c2353cddcb48
Disclosures
6
SEC 8-K · State AG · 6 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
9,290
as filed · SEC 8-K FEDERAL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Polished.com
- Normalized
- polishedcom— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- polished.com
Disclosure history (6)newest first
- FEDERALSEC 8-Kas victim2023-05-26
Polished.com Inc. disclosed a hacking attack on March 16, 2023, impacting its e-commerce checkout page. Attackers extracted personal information (names, addresses, zip codes) and payment card data (numbers, expiration dates, CVVs). The company notified approximately 9,290 individuals and law enforcement. The incident is considered remediated.
- 🦞Maine State AGas victim2023-05-22
Polished.com, an e-commerce company, experienced an external system breach affecting 9,290 individuals. The incident occurred between March 16, 2023, and April 23, 2023, and was discovered on March 17, 2023. The compromised information includes names combined with financial account or credit/debit card numbers and their associated security codes or PINs. Affected residents were notified on May 22, 2023.
- 🦬Montana State AGas victim2023-05-22
Polished.com reported a data breach to the Montana Attorney General. The breach was reported on 2023-05-22. The breach occurred from 3/16/2023 to 4/23/2023. 33 Montana residents were affected.
- 🍁Vermont State AGas victim2023-05-22
Polished.com notified consumers of a security incident where an unauthorized party accessed AppliancesConnection.com between March 16 and April 23, 2023. The attacker acquired payment card information including names, addresses, card numbers, expiration dates, and CVVs. Polished engaged a cybersecurity firm, enhanced security protocols, and established a call center. No specific count of affected individuals was disclosed.
- 🐻California State AGas victim2023-05-22
Polished.com (AppliancesConnection.com) reported that an unauthorized party gained access to its website between March 16 and April 23, 2023, acquiring payment card data (name, address, zip code, card number, expiration date, CVV) entered by customers during that period. The company engaged a cybersecurity firm, secured its systems, and enhanced security protocols. Notice sent May 22, 2023.
- ⛰️New Hampshire State AGas victim2023-05-22
Polished.com notified the NH Attorney General of a cybersecurity incident where an unauthorized actor accessed its website, AppliancesConnection.com, between March 16 and April 23, 2023. The breach potentially exposed payment card information of 57 New Hampshire residents. Polished engaged a cybersecurity firm, mailed notifications, and is enhancing security protocols.