Francesca’s Services Corporation
ent_e64e53a6c55024db81550b91
Disclosures
6
State AG · 6 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
84,275
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Francesca’s Services Corporation
- Normalized
- francesca s— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- francescas.com
Disclosure history (6)newest first
- New Hampshire State AGas victim2018-11-20
Francesca's Services Corporation notified the NH AG of a supply-chain breach involving third-party vendor Annex Cloud. Unauthorized code inserted into Annex Cloud's Social Login app (Dec 2017–Jul 2018) potentially captured customer checkout data including names, emails, passwords, and payment card details. 508 NH residents notified on Nov 19, 2018. Francesca's removed the login feature.
- Oregon State AGas victim2018-11-19
Francesca’s Services Corporation reported a data breach to the Oregon Attorney General. The breach was reported on 2018-11-19. The breach occurred during 12/28/2017 - 12/28/2017. The breach was discovered on 11/8/2018. 84,275 individuals were affected. Notice was sent on 11/19/2018.
- Massachusetts State AGas victim2018-11-19
Francesca's Services Corporation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-11-19. 3,310 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2018-11-19
Francesca's Services Corporation notified customers that a former third-party vendor, Annex Cloud, had unauthorized code on its social login service between Dec 2017 and July 2018. The code potentially captured checkout data including names, addresses, passwords, and payment card details. The feature was removed and customers advised to reset passwords and monitor statements.
- Washington State AGas victim2018-11-19
Francesca's Services Corporation notified the Washington AG of a breach involving third-party vendor Annex Cloud. Unauthorized code inserted into Annex Cloud's Social Login app (Dec 2017–Jul 2018) could capture checkout data including names, passwords, and payment card details. 1,148 WA residents notified starting Nov 19, 2018. App removed.
- California State AGas victim2018-11-19
Francesca’s Services Corporation notified customers of a data breach involving its third-party vendor, Annex Cloud. Unauthorized code detected on Annex Cloud’s login service between December 28, 2017, and July 9, 2018, may have captured checkout information including names, addresses, emails, passwords, and payment card details (number, expiration, CVV). Francesca’s removed the Annex Cloud login feature and advised customers to reset passwords and monitor statements.
Supply-chain cascadesreviewed and confirmed
- Francesca’s Services Corporation’s filing is one of at least 4 in the Social Annex, Inc. supply-chain incident (2018).