STC Holdings LLC
ent_9bd9068ebeb8a949ca42cf55
Disclosures
6
State AG · 6 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
2,334
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- STC Holdings LLC
- Normalized
- stc holdings— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (6)newest first
- New Hampshire State AGas victim2024-12-09
STC Holdings LLC notified the NH Attorney General of a security incident involving its ecommerce site TobaccoPipes.com. A third-party app (FreshClick via BigCommerce) was compromised, allowing a malicious actor to skim credit card data from shoppers between Oct 15 and Nov 7, 2024. STC was notified on Nov 8, 2024. 10 NH residents were affected. STC removed the app, secured systems, and engaged forensic investigators.
- Vermont State AGas victim2024-12-02
STC Holdings (via TobaccoPipes.com) notified consumers of a data breach caused by a compromised third-party application (FreshClick) on its BigCommerce platform. The incident, occurring between Oct 15 and Nov 7, 2024, involved skimming of credit card information. STC Holdings uninstalled the app, secured systems, and engaged forensic investigators.
- Massachusetts State AGas victim2024-11-28
STC Holdings LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-11-28. 53 Massachusetts residents were affected.
- Maine State AGas victim2024-11-28
STC Holdings LLC (tobaccopipes.com) reported a data breach affecting 2,151 individuals, including 5 Maine residents. Unauthorized access occurred between Oct 15 and Nov 7, 2024, via a compromised third-party app (FreshClick) on BigCommerce. Compromised data included names, addresses, and credit card info. Discovered Nov 8, 2024. Notifications sent Nov 27, 2024.
- Montana State AGas victim2024-11-27
STC Holdings LLC (operating TobaccoPipes.com) notified customers of a data security incident involving the third-party BigCommerce application 'FreshClick.' A malicious actor skimmed credit card and personal information from shoppers between Oct 15 and Nov 7, 2024. The company uninstalled the app, secured systems, and engaged forensic investigators.
- Indiana State AGas victim2024-11-27
STC Holdings LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2024-10-15 and was reported on 2024-11-27. 53 Indiana residents were affected. 2,334 individuals affected in total.