Primary Jane Data Breach Lawsuit Investigation

Active investigation · Free, confidential case review
Call (954) 799-5914
Data Breaches / Primary Jane
Active investigation Data breach · E-commerce Notices mailed Aug 20, 2026

Received a July 2026 breach notice from Primary Jane?

Dapeer Law, P.A. is investigating a potential class action against Primary Jane, LLC, a Wilmington, North Carolina online hemp and CBD retailer, on behalf of customers whose credit and debit card numbers, expiration dates, CVV security codes, cardholder names, and billing ZIP codes may have been captured by malicious card-skimming code placed on the company's checkout pages in July 2026.

Submit your claim See what to do No fee unless we recover for you
Breach window
July 13 to 21, 2026
Card-skimming code active on the website
Notification delay
About 1 month
Discovered July 2026, notices August 2026
Credit monitoring
Not offered
No complimentary monitoring in the notice, 1 Massachusetts resident reported
Eligibility

Who may qualify

You may be eligible to participate in a class action if any of the following applies:

  • You received a data breach notification letter from Primary Jane dated July 2026.
  • You used a credit or debit card to make a purchase on primaryjane.com between July 13 and July 21, 2026.
  • You had payment card information entered on Primary Jane's website during the period the malicious code was active, whether or not the order was completed.
  • No proof of harm required to consult with counsel. You do not need to have already suffered identity theft to explore your legal options.
  • Excluded: individuals who did not receive a breach notice and whose information was not involved in the incident.

Not sure if you qualify?

Send us your notice, we'll confirm your eligibility at no cost.

Check eligibility
Background

What happened

On July 21, 2026, Primary Jane, LLC detected unusual activity on its website after its malware protection software flagged an anomaly, according to the security breach notice the company filed with the Massachusetts Attorney General under the Commonwealth's breach statute (MGL c. 93H). The company engaged its external IT support team to conduct a forensic review. That review determined that an unauthorized actor had inserted malicious code into the website that was designed to skim digital credit card data as customer transactions were processed. The company reports the code was active from July 13, 2026 through July 21, 2026.

Primary Jane began mailing notice letters to affected customers on August 20, 2026 and filed the incident with the Massachusetts Attorney General on August 28, 2026, reporting one affected Massachusetts resident. According to the notice, the information that could have been captured at checkout includes credit and debit card numbers, expiration dates, CVV security codes, the cardholder name, and the billing ZIP code. The filing does not identify a complimentary credit monitoring or identity protection offer, and instead directs recipients to contact the three national credit bureaus and review their own financial statements. Whether Primary Jane maintained reasonable security measures on its e-commerce platform before the code was inserted is a central question of our investigation.

Card-skimming attacks of this kind capture payment data in transit, before it is encrypted and transmitted to the payment processor, which means the security of the card issuer's own systems offers no protection. Because the code captured card numbers together with expiration dates, CVV codes, cardholder names, and billing ZIP codes, an unauthorized party would hold every element needed to complete card-not-present transactions online. Customers who used a card on the site during the affected window should treat the card as compromised, request a replacement, and review statements closely even if no fraudulent charge has appeared yet.

Massachusetts Attorney General Payment Card Skimming CVV Exposure E-commerce Breach Card-Not-Present Fraud No Credit Monitoring Offered
Action plan

What to do if you received a letter

1

Keep your notice letter

Do not discard your Primary Jane notice letter. The letter documents that your payment card information was involved in the incident and is important evidence if you decide to participate in a lawsuit.

2

Cancel the affected card and request a replacement

Contact your bank or card issuer, report that the card was used on a website affected by a skimming incident, and ask for a replacement card with a new number. Because the CVV code and billing ZIP code were also involved, simply monitoring the existing card is not enough. Taking these steps does not waive your right to pursue legal action.

3

Place a fraud alert or credit freeze

Contact Equifax, Experian, and TransUnion to place a fraud alert or freeze on your file. Request a free weekly credit report from AnnualCreditReport.com, and use the FTC's IdentityTheft.gov recovery guide. Because full card numbers, CVV codes, and billing ZIP codes were involved, also review every statement covering purchases made on or after July 13, 2026, dispute any charge you do not recognize in writing, and consider placing a fraud alert or a free security freeze with Equifax, Experian, and TransUnion.

4

Speak with a data breach attorney

Consultations with Dapeer Law are free and confidential. We'll review your Primary Jane notice, explain your options, and advise whether you may be eligible to pursue claims under Massachusetts data breach law (MGL c. 93H) or other legal theories.

Submit your notice for a free review

Two minutes online. A licensed attorney reviews every submission.

Submit your claim
Timeline

Breach timeline

July 13, 2026 Passed
Malicious card-skimming code inserted into the Primary Jane website
July 13 to 21, 2026 Passed
Code captures payment card data as customer transactions are processed
July 21, 2026 Passed
Malware protection software flags an anomaly, unusual activity detected
July to August 2026 Passed
External IT support team conducts a forensic review and secures the website
August 20, 2026 Passed
Notice letters mailed to affected customers
August 28, 2026 Passed
Incident reported to the Massachusetts Attorney General
Pending Active
Potential class action filing
Statutes of limitations vary by state and legal theory, typically one to six years. Waiting can permanently bar your claim.
Possible recovery

Compensation you may be entitled to

Out-of-pocket expenses

Credit freezes, identity restoration services, and other costs incurred responding to the breach.

Time spent monitoring

Hours spent reviewing accounts, disputing fraudulent charges, and dealing with identity theft issues.

Identity theft & fraud losses

Unreimbursed funds stolen from accounts, unauthorized credit lines, unauthorized charges on the card you used at checkout, replacement card fees, and the time you spent disputing transactions, or tax refund fraud tied to the breach.

Statutory damages

Certain state data breach and consumer protection statutes provide for fixed damages regardless of actual loss.

Injunctive relief

Court orders requiring Primary Jane to implement stronger e-commerce and checkout security, including file integrity monitoring, content security controls, and prompt notification of affected customers in the event of a future incident.

Compensation categories depend on applicable state law, the types of data exposed, and documented losses. No recovery is guaranteed.

FAQ

Common questions

I received a data breach letter from Primary Jane. What should I do? +

Keep your Primary Jane notice letter, review any purchase you made on primaryjane.com between July 13 and July 21, 2026, contact your bank or card issuer to cancel the card you used and request a replacement, dispute any charge you do not recognize in writing, request your free annual credit reports, consider placing a fraud alert or free security freeze with Equifax, Experian, and TransUnion, document any time or money you spend responding to the incident, and consider speaking with a data breach attorney. If you experience identity theft, you also have the right to file a police report and keep a copy for your records.

Am I eligible to join a class action against Primary Jane? +

Customers who received a Primary Jane notice letter, and customers who used a payment card on primaryjane.com between July 13 and July 21, 2026, are the most direct candidates. Eligibility for any legal claim will also depend on your state of residence, the categories of your information that were involved, and any documented losses or out-of-pocket expenses such as unauthorized charges or replacement card fees. A free case review can help you understand your options.

How much money could I receive from a class action lawsuit? +

Data breach class action recoveries vary significantly. Settlements typically range from a few hundred dollars for basic out-of-pocket losses to several thousand dollars for documented identity theft, with class size, damages, and negotiation all affecting the final amount. No payout is guaranteed, and this investigation has not yet resulted in a settlement.

What personal information was exposed in the breach? +

According to the notice, the malicious code could have captured credit and debit card numbers, expiration dates, CVV security codes, the cardholder name, and the billing ZIP code associated with the card as transactions were processed at checkout. Your individual letter is the most reliable source for exactly what was involved in your case, so we recommend reviewing it carefully and saving a copy.

Did Primary Jane offer free credit monitoring? +

The notice does not identify a complimentary credit monitoring or identity protection offer. Primary Jane instead directs affected customers to contact the three national credit bureaus, review their financial statements, and remain vigilant for unauthorized activity. If your letter does include an enrollment code, use it before the stated deadline, since accepting a monitoring benefit does not waive your right to pursue legal action. This page will be updated if an offer is confirmed.

How many people were affected by the Primary Jane breach? +

The notice filed with the Massachusetts Attorney General reports one affected Massachusetts resident. That figure covers Massachusetts only, and the total number of customers who used a payment card on the website during the July 13 to July 21, 2026 window has not been publicly disclosed. Filings in other states, if any, could raise the total, and this page will be updated if additional information becomes available.

Is there a deadline to take legal action? +

Yes. Statutes of limitations for data breach claims vary by state and legal theory, typically ranging from one to six years. Waiting can permanently bar your claim. Contact us as soon as possible for a free evaluation.

How do I get a copy of the official breach notice? +

Primary Jane filed the security breach notice with the Massachusetts Attorney General, and it can be downloaded from the mass.gov link in the Sources & References section below. If you cannot locate your individual letter, Dapeer Law can help you obtain a copy as part of a free consultation.

References

Sources & references

Attorney advertising. This page is provided for informational purposes only. It does not constitute legal advice or form an attorney-client relationship. Dapeer Law, P.A. is not affiliated with Primary Jane, LLC, Not offered, or any credit bureau. Prior results do not guarantee a similar outcome. All information regarding the data incident is drawn from the official notification filed with Massachusetts Attorney General on August 20, 2026.
Free, confidential case review

Don't let the deadline decide for you. Submit your claim today.

You only have a limited window to act. Our team will review your notice, explain your options, and tell you whether you may be eligible to recover compensation, at no cost to you.

Why Dapeer Law

Practice focusConsumer class actions
Licensed inFL · NY · NJ · IL
Case review fee$0
Response timeSame business day
Free case review
Confidential · 2 minutes
Submit claim →
Previous
Previous

Trellix Data Breach Lawsuit Investigation

Next
Next

RB American Group Data Breach Lawsuit Investigation