21 Air, LLC
ent_cc5c29af363c68d9b81660da
Disclosures
5
State AG · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
419
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- 21 Air, LLC
- Normalized
- 21 air— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- 21air.us
Disclosure history (5)newest first
- Massachusetts State AGas victim2025-12-18
21 Air, LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-12-18. 1 Massachusetts residents were affected.
- New Hampshire State AGas victim2025-12-15
21 Air, LLC notified the New Hampshire Attorney General of a cybersecurity incident discovered on June 3, 2025, involving unauthorized access to a single employee email account. The investigation determined that information for 2 New Hampshire residents was potentially accessed, including names, Social Security numbers, and government IDs. 21 Air engaged third-party specialists, reported the incident to CISA, and sent notices to affected individuals on December 11, 2025, offering 12 months of credit monitoring.
- Maine State AGas victim2025-12-15
21 Air, LLC reported an external system breach (hacking) affecting one employee email account. The incident occurred between March 17 and June 3, 2025, and was discovered on June 3, 2025. Unauthorized access resulted in the exposure of names, SSNs, DOBs, addresses, and government IDs for 419 individuals. 21 Air notified affected individuals on December 11, 2025, and offered 12 months of credit monitoring.
- Indiana State AGas victim2025-12-11
21 Air LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2025-06-03 and was reported on 2025-12-11. 3 Indiana residents were affected. 419 individuals affected in total.
- Nebraska State AGas victim2025-12-11
21 Air, LLC notified affected individuals of a cybersecurity incident discovered on June 3, 2025, involving unauthorized access to an employee email account. The breach exposed names, Social Security numbers, dates of birth, addresses, and government IDs. The company engaged forensic specialists, secured its network, reported to CISA, and offered 12 months of credit monitoring. No evidence of misuse was found.