JAND Inc.
ent_b86efde0f9f91f1792c47263
Disclosures
4
State AG · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
30,170
as filed · State AG CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- JAND Inc.
- Normalized
- jand— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- warbyparker.com
Disclosure history (4)newest first
- Massachusetts State AGas victim2018-12-26
JAND Inc. d/b/a/ Warby Parker reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-12-26. 1,377 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2018-12-24
Warby Parker notified NH AG of credential stuffing incident affecting 177 NH residents. Unauthorized actors used stolen credentials from other breaches to attempt login. No proof of actual data theft, but potential access to names, emails, prescriptions, and last 4 digits of payment cards. Notifications sent Dec 20, 2018.
- California State AGas victim2018-12-21
Warby Parker (JAND Inc.) notified the California AG of a credential stuffing incident where attackers used usernames and passwords obtained from other breaches to attempt unauthorized logins to customer accounts between Sept 25 and Nov 30, 2018. The company detected unusual activity on Nov 26, 2018. Approximately 30,170 California customers were affected. Data potentially accessed included names, emails, prescription info, and last four digits of payment cards. Warby Parker required password resets and reported the incident to the FBI.
- Washington State AGas victim2018-12-20
JAND Inc. d/b/a Warby Parker notified Washington AG of a credential stuffing incident affecting 951 state residents. Unauthorized parties used stolen credentials from other breaches to attempt logins between Sept 25 and Nov 26, 2018. No proof of actual data access was found, but accounts potentially contained names, emails, prescriptions, and partial card info. Customers were required to reset passwords.