Lime Crime, Inc.
ent_f9336b39f0bbdbbee4db81c9
Disclosures
3
State AG · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
1,640
as filed · State AG MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Lime Crime, Inc.
- Normalized
- lime crime— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- limecrime.com
Disclosure history (3)newest first
- New Hampshire State AGas victim2015-03-10
Lime Crime, Inc. filed a supplemental notice with the New Hampshire AG regarding a malware incident on its e-commerce server. Unauthorized individuals installed malicious software between Oct 4, 2014, and Feb 15, 2015, compromising customer PII and payment card data. The incident was discovered on Feb 11, 2015. 189 NH residents were affected. The company engaged forensic investigators, took the site offline, replaced the e-commerce platform, and offered credit monitoring.
- Massachusetts State AGas victim2015-02-27
Lime Crime, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2015-02-27. 1,640 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2015-02-24
Lime Crime, Inc. disclosed that unauthorized individuals installed malicious software on its website server on October 4, 2014. The company discovered the incident on February 11, 2015, after a forensic investigation. The malware potentially compromised personal information of customers who made purchases between October 4, 2014, and February 15, 2015. Affected data includes names, addresses, usernames, passwords, and payment card details (account numbers, expiration dates, security codes) for credit/debit card users. PayPal users had their usernames and passwords compromised but not financial data. Lime Crime took the website offline, replaced its e-commerce platform with a PCI-compliant one, reset passwords, and offered one year of identity protection services via Experian. The incident has been contained and eliminated.