Tween Brands, Inc.
ent_9509b2468bc24869d939b1a6
Disclosures
7
State AG · 7 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
182,823
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Tween Brands, Inc.
- Normalized
- tween brands— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- South Carolina State AGas victim2017-11-08
Tween Brands, Inc. notified South Carolina residents that on September 7, 2017, it discovered unauthorized access attempts to a web server. An unauthorized individual may have accessed a database containing associates' names, dates of birth, and Social Security numbers. The company engaged forensic investigators, removed the server, and offered 12 months of identity protection services.
- California State AGas victim2017-11-03
Tween Brands, Inc. discovered unauthorized access to a web server on September 7, 2017. An attacker may have accessed a database containing vendor portal credentials (usernames/passwords) and associate data (names, dates of birth, SSNs). The company removed the server, engaged forensics, and offered 12 months of identity protection to affected associates.
- Massachusetts State AGas victim2017-11-03
Tween Brands Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-11-03. 4,334 Massachusetts residents were affected. The report records the breach type as electronic.
- Oregon State AGas victim2017-11-03
Tween Brands, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2017-11-03. The breach was discovered on 9/7/2017. 182,823 individuals were affected. Notice was sent on 11/3/2017.
- Washington State AGas victim2017-11-03
Tween Brands, Inc. notified the Washington AG of a cyberattack discovered on September 7, 2017. Unauthorized access to a web server led to a database containing associates' names, DOBs, and SSNs. 2,477 Washington residents were affected. Notices sent November 3, 2017, including 12 months of credit monitoring.
- Montana State AGas victim2017-11-03
Tween Brands, Inc. notified Montana residents of a security incident discovered on September 7, 2017, involving unauthorized access to a web server and subsequent database access. Affected data included names, dates of birth, SSNs, and driver's license numbers. The company engaged forensic investigators and provided 12 months of identity protection services.
- New Hampshire State AGas victim2017-11-03
Tween Brands, Inc. notified the NH Attorney General of a security incident discovered on Sept 7, 2017, where an unauthorized individual accessed a web server and connected to a database containing associates' PII (names, DOB, SSNs). Notices sent Nov 3, 2017, to 919 NH residents. Remediation included enhanced security measures and 12-month credit monitoring.