Guidecraft, Inc
ent_ddb3377bba5f9f500f82609b
Disclosures
7
State AG · 7 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
10,006
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Guidecraft, Inc
- Normalized
- guidecraft— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- guidecraft.com
Disclosure history (7)newest first
- New Hampshire State AGas victim2023-03-27
Guidecraft, Inc. notified the NH AG of a data event affecting 67 NH residents. Unauthorized code was injected into guidecraft.com between Sept 2021 and Dec 2022, exposing customer checkout data (PII, credit/debit card info). A vendor backup error further exposed transactions from Feb 2023. Guidecraft engaged forensic specialists, secured the site, and notified affected individuals and credit bureaus.
- Maine State AGas victim2023-03-23
Guidecraft, Inc. reported an external system breach (hacking) occurring on 09/21/2021, discovered on 12/29/2022. The incident affected 10,006 individuals, including 56 Maine residents. Compromised data included names and financial account or credit/debit card numbers. Written notification was sent on 03/23/2023.
- California State AGas victim2023-03-23
Guidecraft, Inc. disclosed that unauthorized code was entered into its e-commerce website between September 21, 2021, and December 30, 2022, potentially exposing customer names, addresses, and credit/debit card numbers. The company became aware of suspicious activity on December 29, 2022. Additionally, a vendor error potentially exposed credit card purchases from February 7-8, 2023. Guidecraft engaged forensic specialists, secured the website, and enhanced security procedures.
- Montana State AGas victim2023-03-23
Guidecraft, Inc. notified customers of a data breach involving unauthorized access to its e-commerce website. Suspicious activity was detected on December 29, 2022, stemming from unauthorized code entry between September 2021 and December 2022, plus a vendor error exposing credit card data in February 2023. Impacted data included names, addresses, and credit/debit card numbers. Third-party forensic specialists were engaged.
- Massachusetts State AGas victim2023-03-23
Guidecraft, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-03-23. 487 Massachusetts residents were affected. The report records the breach type as electronic.
- Indiana State AGas victim2023-03-23
Guidecraft Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2021-09-21 and was reported on 2023-03-23. 133 Indiana residents were affected. 10,006 individuals affected in total.
- Vermont State AGas victim2023-02-23
Guidecraft, Inc. notified consumers of a data breach involving unauthorized code injection on its e-commerce website (guidecraft.com). The incident, discovered on December 29, 2022, potentially exposed customer names, billing/shipping addresses, and credit/debit card numbers for transactions made between September 2021 and February 2023. Guidecraft engaged forensic specialists and secured the site. 36 Rhode Island residents were explicitly identified as impacted.