CBD Industries, LLC
ent_b2b22b389de7f96600087f32
Disclosures
13
State AG · 9 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
42,694
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CBD Industries, LLC
- Normalized
- cbd industries— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (13)newest first
- New Hampshire State AGas victim2021-03-04
CBD Industries, LLC, an online retailer, issued a supplemental notice to the New Hampshire Attorney General regarding a data event involving malicious code on its eCommerce platforms (hempsynergy.com, pawcbd.com). The code, inserted between March 30 and May 18, 2020, risked skimming customer transaction data including names, emails, billing addresses, credit/debit card numbers, and bank account numbers. The incident was discovered on January 19, 2021. 332 individuals nationwide were at risk, including 13 New Hampshire residents. CBD Industries notified federal law enforcement, provided one year of TransUnion credit monitoring, and implemented additional technical security measures.
- Maine State AGas victim2021-02-23
CBD Industries, LLC experienced an external system breach between March 30, 2020, and May 18, 2020, discovered on January 19, 2021. The incident affected 1,845 individuals, compromising names and financial account or credit/debit card numbers along with their access codes. The company provided written notifications and offered 12 months of credit monitoring and identity restoration services through TransUnion.
- Montana State AGas victim2021-02-23
CBD Industries, LLC notified Montana AG of a data privacy incident affecting 168 residents. Malicious code was inserted into the eCommerce platform between March 30 and May 18, 2020, risking the skim of customer PII and financial data. The company engaged forensic investigators, notified law enforcement, and offered one year of identity monitoring.
- Illinois State AGas victim2021-01-01
CBD INDUSTRIES, LLC filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-068). The register records the breach as discovered on January 19, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Massachusetts State AGas victim2020-10-02
CBD Industries, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-10-02. 1,495 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2020-09-29
CBD Industries, LLC notified the California Attorney General of a data breach affecting its eCommerce platform. An unauthorized third party stole credentials used to access the platform. Customers who placed orders between March 30, 2020, and May 18, 2020, were at risk. Potentially compromised data included names, email and billing addresses, credit/debit card numbers, expiration dates, security codes, and bank account numbers. The company engaged law enforcement and offered one year of identity monitoring.
- New Hampshire State AGas victim2020-09-29
CBD Industries, LLC notified NH AG of a data privacy incident where malicious code was added to its eCommerce platform, risking customer data (names, emails, billing addresses, credit/debit card numbers, bank account numbers) for orders placed between March 30 and May 18, 2020. 332 NH residents were at risk. The company engaged forensic investigators, notified law enforcement, and is offering one year of free identity monitoring.
- Montana State AGas victim2020-09-29
CBD Industries, LLC reported a data privacy incident impacting its eCommerce platform. Unauthorized access occurred between April 14 and April 19, 2025. The incident involved the exfiltration of customer PII, including government IDs and financial account data. The company engaged forensic counsel and law enforcement, and is offering one year of identity monitoring to affected individuals.
- Oregon State AGas victim2020-09-29
CBD Industries, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2020-09-29. The breach occurred during 3/30/2020 - 5/8/2020, 5/14/2020 - 5/18/2020. The breach was discovered on 8/26/2020. 42,694 individuals were affected. Notice was sent on 9/28/2020.
- Washington State AGas victim2020-09-29
CBD Industries, LLC, an online retailer, reported a cybersecurity incident where malicious code was added to its eCommerce platform, potentially skimming customer transaction data including names, emails, billing addresses, and credit/debit card numbers. The incident affected transactions between March 30, 2020, and May 18, 2020. The company notified law enforcement, offered one year of credit monitoring, and reported 1,088 affected individuals, including 48 Washington residents.
- Maine State AGas victim2020-09-29
CBD Industries, LLC experienced an external system breach between March and May 2020, discovered on August 26, 2020. The breach affected 42,694 individuals, including 192 Maine residents. The compromised information included names and financial account or credit/debit card numbers with their corresponding security codes, access codes, or PINs. The company notified affected individuals and offered 12 months of identity monitoring services through TransUnion.
- Indiana State AGas victim2020-09-28
CBD Industries, LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2020-03-30 and was reported on 2020-09-28. 782 Indiana residents were affected. 42,694 individuals affected in total.
- Illinois State AGas victim2020-01-01
CBD INDUSTRIES filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-387). The register records the breach as discovered on March 30, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.