Dollar Shave Club, Inc.
ent_8e153a02f51f9be00fb3e24b
Disclosures
4
State AG · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
15
as filed · State AG MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Dollar Shave Club, Inc.
- Normalized
- dollar shave club— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- dollarshaveclub.com
Disclosure history (4)newest first
- Montana State AGas victim2018-07-16
Dollar Shave Club, Inc. notified Montana members of unauthorized account access between May 26 and June 25, 2018. Attackers used stolen email/password combinations to purchase e-gift cards. Affected data included names, addresses, emails, phone numbers, and last four digits of payment cards. The company refunded purchases, voided codes, and implemented login notifications and gift card limits.
- Massachusetts State AGas victim2018-06-27
Dollar Shave Club, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-06-27. 15 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2018-06-27
Dollar Shave Club, Inc. notified the New Hampshire Attorney General of a credential-stuffing incident affecting 7 NH residents. Between May 26 and June 13, 2018, unauthorized actors used stolen email/password combinations to access customer accounts, view PII (name, address, email, phone), and purchase e-gift cards using hashed payment card data (last 4 digits only). The company disabled accounts, reset passwords, refunded purchases, voided codes, blocked IPs, and filed an FBI IC3 complaint.
- California State AGas victim2018-04-04
On March 21, 2018, Dollar Shave Club identified unauthorized login attempts using credentials obtained from other sources (credential stuffing). The attacker used valid email/password combinations to access customer accounts. Dollar Shave Club blocked suspicious IPs, reset passwords for affected accounts, and limited login attempts. Affected data included names, addresses, and the last four digits of payment cards. No full payment card data or other financial information was compromised.