Provo Craft & Novelty, Inc.
ent_8f765a7de715dd23b023b806
Disclosures
4
State AG · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
39,353
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Provo Craft & Novelty, Inc.
- Normalized
- provo craft novelty— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- Oregon State AGas victim2017-10-12
Provo Craft & Novelty, Inc., d/b/a Cricut reported a data breach to the Oregon Attorney General. The breach was reported on 2017-10-12. The breach occurred during 5/27/2017 - 7/12/2017. The breach was discovered on 9/13/2017. 39,353 individuals were affected. Notice was sent on 10/5/2017.
- Massachusetts State AGas victim2017-10-12
Provo Craft & Novelty, Inc., d/b/a Circuit reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-10-12. 434 Massachusetts residents were affected. The report records the breach type as electronic.
- Washington State AGas victim2017-10-06
Provo Craft & Novelty, Inc. (d/b/a Cricut) notified the WA AG of a cyberattack on its checkout page (shop.cricut.com) between May 27 and July 12, 2017. Discovered Sept 13, 2017. Malware scraped payment card numbers, security codes, expiration dates, names, addresses, and phone numbers. 773 WA residents affected. Notified Oct 5, 2017. Offered 12 months credit monitoring.
- New Hampshire State AGas victim2017-10-06
Provo Craft & Novelty, Inc. d/b/a Cricut notified the NH AG of a cyberattack on its checkout page (shop.cricut.com) between May 27 and July 12, 2017. The attack scraped payment card numbers, security codes, expiration dates, names, addresses, and phone numbers. Provo Craft discovered the incident on September 13, 2017, engaged forensic experts, removed malware, and notified law enforcement. 132 NH residents were affected. Notifications were mailed on October 5, 2017, offering 12 months of credit monitoring.