Chief River Nursery experienced a cybersecurity incident between February 12, 2026, and March 17, 2026, in which payment card data was unauthorizedly copied from its checkout page. The company discovered the breach on May 1, 2026, and notified affected consumers on June 1, 2026, as reported to the Maine Attorney General.
The compromised data types included names and payment card information. While 72 Maine residents were affected, the total number of affected individuals nationally has not been publicly disclosed. There is no indication of SSN or medical data involvement.
Details about the full scope of the breach and any further actions may emerge. Consumer notifications began on June 1, 2026, but the process of notifying all affected individuals can take time.