Clustered 4 filings across 4 jurisdictions · filed Aug 9, 2023. View entity profile → Other incidents for this victim →
incident inc_20f98519a1a14cc7 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Identity (basic) · Financial account · Financial credentials
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
CA ME NH VT
all State AG
Earliest sighting first · deep chronology in Litigation Timeline
Nov 24, 2021 → Dec 14, 2022
When the intrusion reportedly occurred, per the linked filings
May 3, 2023
Reported by VERMONT AG filing
Jun 8, 2023
Reported by MAINE AG filing
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Vermont Christmas Company notified consumers of a data breach involving its third-party e-commerce vendor, CommerceV3. Unauthorized access occurred between Nov 2021 and Dec 2022. Impacted data included names, billing addresses, emails, payment card numbers, CVVs, and expiration dates. CommerceV3 implemented additional security measures and notified law enforcement. Vermont Christmas Company is reviewing vendor procedures and notifying regulators.
Vermont Christmas Company notified customers of unauthorized access to its third-party vendor, CommerceV3, between Nov 24, 2021, and Dec 14, 2022. Potentially impacted data includes name, billing address, email, payment card number, CVV, and expiration date. The company is reviewing vendor procedures and notifying regulators.
Vermont Christmas Company notified New Hampshire AG of a third-party vendor breach involving CommerceV3. Unauthorized access to CommerceV3 systems occurred between Nov 24, 2021 and Dec 14, 2022. Cardholder information was potentially impacted. VCC is reviewing vendor policies and notifying regulators. No specific count of affected individuals was disclosed in this filing.
Vermont Christmas Company reported a third-party vendor incident on 11/24/2021, discovered on 06/08/2023. 12,533 individuals were affected, including 152 Maine residents. The breach involved names and financial account/credit card numbers. Written notification was sent on 08/09/2023.
Affected (this filing): 12,533