PalmFlex, Inc
ent_c85ff0a6dff9d485b8346386
Disclosures
3
State AG · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
19
as filed · State AG MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- PalmFlex, Inc
- Normalized
- palmflex— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (3)newest first
- New Hampshire State AGas victim2026-07-21
PalmFlex Inc. notified New Hampshire residents of a security incident discovered on June 25, 2026, where a third party accessed the administrative interface and injected unauthorized code into the website. The code was immediately removed, and access was remediated. 12 New Hampshire residents were notified as payment card information may have been compromised. The company engaged cybersecurity specialists, reset credentials, and implemented additional security controls.
- Massachusetts State AGas victim2026-07-15
PalmFlex, Inc. notified Massachusetts customers on July 15, 2026, that payment card information may have been accessed by an unauthorized third party. The company engaged hosting providers and cybersecurity specialists to investigate, secure systems, reset credentials, and implement additional access restrictions. No specific count of affected individuals was provided.
- Nebraska State AGas victim2025-07-22
PalmFlex Inc. notified Nebraska customers of a data breach occurring between April 2, 2026, and June 25, 2026. A third party accessed the administrative interface and injected unauthorized code, potentially compromising payment card information for orders placed during that window. PalmFlex engaged cybersecurity specialists, reset credentials, and implemented additional security controls. Notices were sent on July 15, 2026.