Heirloom Roses
ent_d57fc71449a37e932e77c5d2
Disclosures
9
State AG · 9 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
52,206
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Heirloom Roses
- Normalized
- heirloom roses— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (9)newest first
- New Hampshire State AGas victim2021-12-23
Heirloom Roses notified the NH AG of a security incident where malicious code on its website captured customer credit card data and names from Feb-Oct 2021. Discovered Aug 12, 2021. 266 NH residents affected. Remediation included removing code, new payment processor, and offering 12 months credit monitoring.
- Maine State AGas victim2021-12-17
Heirloom Roses, a commercial entity, reported a cybersecurity incident occurring between February 24, 2021, and October 26, 2021. The breach involved malicious code placed on the company's website, resulting in unauthorized access to customer data. Approximately 52,206 individuals were affected, including 243 Maine residents. Compromised data included names and financial account or credit/debit card numbers. The company provided written notification and offered one year of credit monitoring and identity theft protection services through Kroll.
- Oregon State AGas victim2021-12-17
Heirloom Roses reported a data breach to the Oregon Attorney General. The breach was reported on 2021-12-17. The breach occurred during 2/24/2021 - 10/26/2021. The breach was discovered on 11/17/2021. 52,206 individuals were affected. Notice was sent on 12/17/2021.
- California State AGas victim2021-12-17
Heirloom Roses experienced a data breach involving malicious code (skimmer) added to its website to capture credit card data. The unauthorized access occurred between February 2021 and October 26, 2021, and was discovered on August 12, 2021. Affected data includes names and credit card information. The company engaged forensic specialists, removed the code, and offered 12 months of identity monitoring.
- Montana State AGas victim2021-12-17
Heirloom Roses notified affected individuals of a payment card skimming incident. Malicious code was added to the website between February and October 2021, capturing credit card data. The company engaged forensic specialists, removed the code, and offered 12 months of identity monitoring. Discovery was reported on August 12, 2021.
- Washington State AGas victim2021-12-17
Heirloom Roses, a retail business, notified the Washington AG of a cyberattack where malicious code on its website captured customer names and credit card data. The incident occurred between Feb 12 and Oct 26, 2021, and was discovered on Aug 12, 2021. 3,118 Washington residents were affected. Heirloom engaged forensic specialists, removed the code, changed payment processors, and offered 12 months of credit monitoring.
- Massachusetts State AGas victim2021-12-17
Heirloom Roses reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-12-17. 1,383 Massachusetts residents were affected. The report records the breach type as electronic.
- Indiana State AGas victim2021-12-17
Heirloom Roses reported a data breach to the Indiana Attorney General. The breach occurred on 2021-02-24 and was reported on 2021-12-17. 807 Indiana residents were affected. 52,206 individuals affected in total.
- Illinois State AGas victim2021-01-01
HEIRLOOM ROSES filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-514). The register records the breach as discovered on August 12, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.