Avery Products Corporation
ent_a9b972f7e5bf51b632635f16
Disclosures
17
State AG · 13 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
67,000
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Avery Products Corporation
- Normalized
- avery products— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (17)newest first
- Maryland State AGas victim2025-11-13
Avery Products Corporation experienced a ransomware attempt on its payment processing application between July 18, 2024, and December 9, 2024. Malicious software was inserted into the website's cart to scrape payment card information (including CVV and expiration dates) and customer PII. 1,237 Maryland residents were affected. Avery engaged forensic investigators, secured its systems, and provided one year of credit monitoring. The incident status is contained.
- California State AGas victim2025-02-11
Avery Products Corporation experienced a ransomware attack discovered on December 9, 2024. An unauthorized actor inserted malicious software to scrape credit card information from avery.com between July 18, 2024, and January 5, 2025. Affected data includes names, addresses, email, phone, payment card numbers, CVV, expiration dates, and purchase amounts. The company engaged forensic experts, reported to regulators, and is offering 12 months of credit monitoring.
- Montana State AGas victim2025-02-07
Avery Products Corporation notified affected individuals of a ransomware attack discovered on December 9, 2024. Unauthorized actors scraped credit card information, names, addresses, and phone numbers from avery.com between July 18, 2024, and January 5, 2025. The company engaged forensic experts, reported the incident to regulators, and offered 12 months of credit monitoring.
- Maine State AGas victim2025-02-06
Avery Products Corporation reported a ransomware attack on its e-commerce site (avery.com) occurring between July 18, 2024, and January 5, 2025. The incident affected 67,000 individuals nationwide, including 523 Maine residents. Compromised data included names, addresses, and full payment card details (CVV, expiration). The company engaged forensic experts, notified regulators, and offered 12 months of credit monitoring.
- New Hampshire State AGas victim2025-02-05
Avery Products Corporation issued a supplemental notice to the NH AG regarding a ransomware attempt and malware incident affecting customer payment card data on avery.com. The incident occurred between July 18, 2024, and January 5, 2025. Malware embedded in the website cart scraped payment information. 400 New Hampshire residents were affected. Avery engaged forensic investigators and provided credit monitoring.
- Illinois State AGas victim2025-02-01
AVERY PRODUCTS CORPORATION filed a data-breach notice with the Illinois Attorney General in February 2025 (case 25-02-022). The register records the breach as discovered on July 18, 2024. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Vermont State AGas victim2025-01-29
Avery Products Corporation notified consumers of a ransomware attack discovered on December 9, 2024. Between July 18, 2024, and January 5, 2025, an unauthorized actor scraped credit card information, names, addresses, and CVVs from avery.com. The incident was reported to state regulators and AGs. Affected individuals are offered 12 months of credit monitoring.
- Oregon State AGas victim2025-01-16
Avery Products Corporation reported a data breach to the Oregon Attorney General. The breach was reported on 2025-01-16. The breach occurred during 7/18/2024 - 12/9/2024. The breach was discovered on 12/9/2024. 61,100 individuals were affected. Notice was sent on 1/16/2025.
- Indiana State AGas victim2025-01-16
Avery Products Corporation reported a data breach to the Indiana Attorney General. The breach occurred on 2024-07-18 and was reported on 2025-01-16. 1,195 Indiana residents were affected. 61,192 individuals affected in total.
- California State AGas victim2025-01-16
Avery Products Corporation experienced a ransomware attack affecting its website avery.com between July 18, 2024, and December 9, 2024. The company became aware of the incident on December 9, 2024. An unauthorized actor inserted malicious software to scrape credit card information, including CVV numbers and expiration dates, as well as names, addresses, and contact details. While initial evidence did not show exfiltration, subsequent reports of fraudulent charges suggest data may have been acquired. Avery engaged forensic experts, notified regulators, and is offering 12 months of credit monitoring to affected individuals.
- Nebraska State AGas victim2025-01-15
Avery Products Corporation, a manufacturer and supplier of offices supplies and print products. entity filed a data breach notification with the Nebraska Attorney General. The breach was discovered on 2024-12-09 according to the AG's register. The breach is dated 2024-07-18 to 2024-12-09. Nebraska residents were notified on 2025-01-15.
- Delaware State AGas victim2025-01-15
Avery Products Corporation reported a data breach to the Delaware Attorney General. The breach occurred on 2024-07-18. It was discovered on 2024-12-09. Notice was filed on 2025-01-15. 205 Delaware residents were affected. 61,193 individuals affected in total. Information involved: authentication, financial account.
- New Hampshire State AGas victim2025-01-13
Avery Products Corporation notified the NH AG of a ransomware attempt on its payment processing application between July 18 and Dec 9, 2024. Malicious software scraped payment card info from avery.com. 372 NH residents affected. Avery engaged forensic investigators, secured systems, and offered 12 months of credit monitoring.
- Massachusetts State AGas victim2025-01-13
Avery Products Corporation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-01-13. 1,791 Massachusetts residents were affected.
- Maine State AGas victim2025-01-13
Avery Products Corporation disclosed a ransomware attack occurring between July 18 and December 9, 2024. The incident compromised names, addresses, and payment card data (including CVV) for approximately 61,193 individuals, including 460 Maine residents. The company engaged forensic experts, notified regulators, and provided 12 months of credit monitoring.
- Washington State AGas victim2025-01-10
Avery Products Corporation reported a ransomware attack on its payment processing application (avery.com) between July 18, 2024, and January 5, 2025. The incident compromised customer names, addresses, and payment card details (including CVV). 1,724 Washington residents were affected. The company engaged forensic investigators and provided 12 months of credit monitoring.
- Illinois State AGas victim2025-01-01
AVERY PRODUCTS CORPORATION filed a data-breach notice with the Illinois Attorney General in January 2025 (case 25-01-033). The register records the breach as discovered on July 18, 2024. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.