LEM Products Direct LLC
ent_a541279bc1dbdf7899aa98d4
Disclosures
9
State AG · 9 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
29,394
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- LEM Products Direct LLC
- Normalized
- lem products direct— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (9)newest first
- Oregon State AGas victim2023-07-20
LEM Products Direct LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2023-07-20. The breach occurred during 11/24/2021 - 12/14/2022. The breach was discovered on 6/6/2023. 29,394 individuals were affected. Notice was sent on 7/13/2023.
- Maine State AGas victim2023-07-13
LEM Products Direct LLC reported a data breach affecting 138 Maine residents, which occurred due to a cybersecurity incident at its third-party e-commerce vendor, CommerceV3. The breach, lasting from November 24, 2021, to December 14, 2022, was discovered on June 6, 2023. The compromised information includes names in combination with financial account or credit/debit card numbers and their security codes.
- Montana State AGas victim2023-07-13
LEM Products Direct LLC notified Montana residents that its third-party e-commerce platform provider, CommerceV3, experienced unauthorized access to its systems between November 2021 and December 2022. The incident potentially exposed customer payment card information, including names, billing addresses, card numbers, and CVVs. CommerceV3 conducted a forensic investigation and implemented additional security measures.
- New Hampshire State AGas victim2023-07-13
LEM Products Direct LLC notified New Hampshire AG of a third-party breach involving its e-commerce platform provider, CommerceV3. Unauthorized access to cardholder data occurred between Nov 24, 2021 and Dec 14, 2022. CommerceV3 discovered the potential access on May 3, 2023, after forensic investigation. LEM Products Direct LLC notified affected individuals on July 13, 2023.
- California State AGas victim2023-07-13
LEM Products Direct LLC notified customers that an unauthorized party accessed its third-party e-commerce platform, CommerceV3, between November 24, 2021, and December 14, 2022. The incident potentially exposed payment card information, including card numbers, expiration dates, and CVVs, along with names, email addresses, and billing addresses. CommerceV3 discovered the access on May 3, 2023, and notified LEM on June 6, 2023. LEM implemented additional security measures and advised customers to monitor their accounts.
- Massachusetts State AGas victim2023-07-13
LEM Products Direct LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-07-13. 232 Massachusetts residents were affected. The report records the breach type as electronic.
- Washington State AGas victim2023-07-06
LEM Products Direct LLC reported a third-party vendor breach involving CommerceV3. Unauthorized access to CommerceV3 systems occurred between Nov 24, 2021 and Dec 14, 2022. LEM was notified on June 6, 2023. Payment card data (numbers, CVVs, expiration) for 640 Washington residents was compromised. Notifications mailed July 6, 2023.
- Indiana State AGas victim2023-07-06
LEM Products Direct LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2021-11-24 and was reported on 2023-07-06. 948 Indiana residents were affected. 29,394 individuals affected in total.
- Illinois State AGas victim2023-01-01
LEM PRODUCTS DIRECT LLC filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-463). The register records the breach as discovered on November 24, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
Supply-chain cascadesreviewed and confirmed
- LEM Products Direct LLC’s filing is one of at least 31 in the CommerceV3 supply-chain incident (2023).