KandyPens, Inc.
ent_c51ba5424f7ec3c4e53d12a5
Disclosures
6
State AG · 6 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
39,457
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- KandyPens, Inc.
- Normalized
- kandypens— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (6)newest first
- Massachusetts State AGas victim2020-04-29
KandyPens, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-04-29. 1,646 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2020-04-21
KandyPens, Inc. notified the NH Attorney General of a data security incident discovered in January 2020. Unauthorized access to the online payment platform compromised customer names and credit/debit card details (including CVVs) entered between March 7, 2019, and February 13, 2020. 292 NH residents were notified on April 20, 2020. KandyPens engaged forensic investigators, remediated the vulnerability, and increased monitoring.
- California State AGas victim2020-04-20
KandyPens, Inc. experienced a data security incident where an unauthorized user gained access to its online payment platform between March 7, 2019, and February 13, 2020. The company became aware of suspicious activity in January 2020. Compromised data may include names, credit/debit card numbers, expiration dates, and security codes. The vulnerability was fixed, and monitoring was increased.
- Indiana State AGas victim2020-04-20
KandyPens, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2019-03-07 and was reported on 2020-04-20. 554 Indiana residents were affected. 39,457 individuals affected in total.
- Oregon State AGas victim2020-04-20
KandyPens, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2020-04-20. The breach occurred during 3/7/2019 - 2/13/2020. The breach was discovered on 2/12/2020. 39,457 individuals were affected. Notice was sent on 4/20/2020.
- Montana State AGas victim2020-04-20
KandyPens, Inc. notified Montana residents of a data security incident discovered in January 2020. Unauthorized access to the online payment platform occurred between March 7, 2019, and February 13, 2020, potentially exposing names and credit/debit card details. The company engaged forensic experts, fixed the vulnerability, and enhanced monitoring.