CommerceV3
ent_a79aadc9bc84abd5662ddf6d
Disclosures
5
State AG · 3 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
5,001
as filed · State AG SC
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CommerceV3
- Normalized
- commercev3— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- commercev3.com
Disclosure history (5)newest first
- Vermont State AGas reporting2023-07-24
Jack Stack Barbecue notified consumers of a data breach involving its third-party e-commerce platform, CommerceV3. The incident occurred between November 24, 2021, and December 14, 2022, affecting customer payment card data, CVV codes, and personal information. Jack Stack learned of the breach on June 19, 2023, and sent notices on July 24, 2023. No evidence of misuse was found.
- Montana State AGas victim2023-07-21
Creedmoor Sports notified customers that CommerceV3, its e-commerce platform provider, experienced a data security incident. Unauthorized access occurred between Nov 24, 2021 and Dec 14, 2022. Cardholder data (name, email, billing address, card number, CVV, expiration) was potentially accessed. Creedmoor contacted CommerceV3 for security updates and offered 12 months of credit monitoring.
- South Carolina State AGas victim2023-07-05
CommerceV3, a third-party payment processor, experienced unauthorized access to its systems between Nov 2021 and Dec 2022. Young’s Premium Foods, a retailer using CommerceV3, notified affected individuals in June 2023. Data potentially involved included names, emails, billing addresses, and payment card details (PAN, CVV, expiry). No misuse was identified, but risk remains. 14 Rhode Island residents were explicitly noted as impacted.
- Montana State AGas victim2023-06-29
Jerry Baker notified Montana residents that its third-party e-commerce platform provider, CommerceV3, experienced unauthorized access to its systems between Nov 24, 2021 and Dec 14, 2022. The incident potentially exposed customer names, emails, billing addresses, and full payment card details (including CVV). Jerry Baker learned of the incident on June 7, 2023.
- Montana State AGas victim2023-06-16
John & Kira’s Chocolates notified customers that CommerceV3, its third-party e-commerce platform, experienced unauthorized access to systems processing payment card data. The incident affected customer information including names, emails, billing addresses, and payment card details (number, CVV, expiration) for orders placed between November 24, 2021, and July 1, 2022. CommerceV3 engaged forensic experts and implemented security upgrades. The investigation confirmed the threat was eliminated.
Supply-chain cascadesreviewed and confirmed
- CommerceV3 supply-chain incident (2023)2023-06-15 – 2024-01-2531 organizations linked