SERRV International
ent_6d6883ce88494dc5fa17cc3c
Disclosures
9
State AG · 9 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
16,221
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- SERRV International
- Normalized
- serrv international— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- serrv.org
Disclosure history (9)newest first
- New Hampshire State AGas victim2023-08-29
SERRV International, a fair trade nonprofit, notified the New Hampshire Attorney General of a data security incident involving its third-party e-commerce platform, CommerceV3. An unauthorized party accessed CommerceV3's systems between November 24, 2021, and December 14, 2022. The incident potentially compromised customer payment card information. SERRV notified 142 New Hampshire residents on August 25, 2023. CommerceV3 conducted a forensic investigation with third-party experts and implemented additional security measures.
- Massachusetts State AGas victim2023-08-29
SERRV International reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-08-29. 734 Massachusetts residents were affected. The report records the breach type as electronic.
- Washington State AGas victim2023-08-29
SERRV International, a 501(c)(3) nonprofit, notified 630 Washington residents of a data security incident involving its third-party e-commerce platform, CommerceV3. Unauthorized access occurred between Nov 24, 2021 and Dec 14, 2022. SERRV was notified on July 17, 2023. Impacted data included names, emails, billing addresses, and payment card details. Notifications were sent on Aug 25, 2023.
- Oregon State AGas victim2023-08-29
SERRV International reported a data breach to the Oregon Attorney General. The breach was reported on 2023-08-29. The breach occurred during 11/24/2021 - 12/14/2022. The breach was discovered on 7/17/2023. 16,221 individuals were affected. Notice was sent on 8/25/2023.
- Maine State AGas victim2023-08-29
SERRV International, a non-profit organization, reported a data breach affecting 157 Maine residents due to an incident at its third-party vendor, CommerceV3. The breach occurred between November 24, 2021, and December 14, 2022, and was discovered on July 17, 2023. The compromised information includes financial account numbers or credit/debit card numbers along with their security codes, access codes, passwords, or PINs. Customers were notified on August 25, 2023.
- California State AGas victim2023-08-28
SERRV International notified customers of a data security incident involving its third-party e-commerce platform, CommerceV3. An unauthorized party accessed CommerceV3 systems between November 24, 2021, and December 14, 2022. CommerceV3 identified potentially impacted SERRV customers on July 17, 2023. Affected data may include name, email, billing address, payment card number, expiration date, and security code. SERRV and CommerceV3 conducted forensic investigations and implemented additional security measures.
- Montana State AGas victim2023-08-28
SERRV International notified customers of a data breach involving its third-party e-commerce platform, CommerceV3. Unauthorized access occurred between Nov 2021 and Dec 2022. Impacted data included names, emails, billing addresses, and payment card details. SERRV was notified by CommerceV3 on July 17, 2023.
- Indiana State AGas victim2023-08-25
SERRV International reported a data breach to the Indiana Attorney General. The breach occurred on 2021-11-24 and was reported on 2023-08-25. 212 Indiana residents were affected. 16,221 individuals affected in total.
- Illinois State AGas victim2023-01-01
SERRV INTERNATIONAL filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-599). The register records the breach as discovered on November 24, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
Supply-chain cascadesreviewed and confirmed
- SERRV International’s filing is one of at least 31 in the CommerceV3 supply-chain incident (2023).