Roots & Harvest Direct LLC
ent_74d3819e4a5313f0cb5816b4
Disclosures
5
State AG · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
4,073
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Roots & Harvest Direct LLC
- Normalized
- roots harvest direct— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- Maine State AGas victim2023-07-14
Roots & Harvest Direct LLC reported a data breach affecting 26 Maine residents after a cybersecurity incident at its third-party e-commerce vendor, CommerceV3. The incident occurred between November 24, 2021, and December 14, 2022, and was discovered on June 6, 2023. The compromised data includes names and financial account or credit/debit card numbers, along with security codes, access codes, or passwords.
- Massachusetts State AGas victim2023-07-13
Roots & Harvest Direct LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-07-13. 66 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2023-07-13
Roots & Harvest Direct LLC notified the NH Attorney General of a third-party vendor breach involving CommerceV3. Unauthorized access to CommerceV3's systems occurred between Nov 24, 2021 and Dec 14, 2022. Cardholder data for 27 NH residents was potentially accessed. Notification letters were mailed on July 13, 2023.
- Montana State AGas victim2023-07-13
Roots & Harvest Direct LLC notified customers that its third-party e-commerce platform provider, CommerceV3, experienced unauthorized access to systems between Nov 2021 and Dec 2022. Cardholder data including names, emails, billing addresses, card numbers, and CVVs were potentially accessed. CommerceV3 conducted forensic investigations and implemented additional security measures.
- Indiana State AGas victim2023-07-06
Roots & Harvest Direct LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2021-11-24 and was reported on 2023-07-06. 99 Indiana residents were affected. 4,073 individuals affected in total.
Supply-chain cascadesreviewed and confirmed
- Roots & Harvest Direct LLC’s filing is one of at least 31 in the CommerceV3 supply-chain incident (2023).