High Mowing Organic Seeds Data Breach Exposes Financial Account and Card Information

Retail data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: June 2026

What Happened in the High Mowing Organic Seeds Data Breach?

High Mowing Organic Seeds recently filed a formal notice with the Vermont Attorney General confirming a data breach. The filing reveals that unauthorized parties gained access to sensitive customer financial information. This disclosure puts the seed company among a growing list of retailers reporting payment data compromises this year.

According to the notification, the exposed data includes financial account codes along with credit and debit account information. However, the filing does not specify exactly how the intrusion occurred. It also does not state precisely when the unauthorized access began, so that detail has not been publicly disclosed.

Because the company chose to notify Vermont’s Attorney General, state law required this step once officials confirmed that resident data had been compromised. As a result, affected customers can expect direct notification letters if they have not already received one. The investigation into the full scope of the incident may still be ongoing.

In addition, companies typically bring in forensic security experts after discovering this kind of exposure. While High Mowing Organic Seeds has not detailed its specific investigative steps publicly, the filing itself confirms that a breach involving financial data did occur. This type of regulatory notice is usually filed only after an organization has verified that consumer information was compromised.

Who was affected?

The breach appears to affect customers who made purchases or maintained payment information with High Mowing Organic Seeds. Because the company sells seeds and gardening products nationally, this incident likely affects buyers across many states, not just Vermont residents. The Vermont filing exists because state law requires notification whenever a Vermont resident’s data is involved.

The exact number of people affected has not been publicly disclosed. Similarly, the filing does not clarify whether employees, in addition to customers, had their information exposed. Anyone who has placed an order or stored payment details with the company during the relevant timeframe should consider themselves potentially affected.

Given the nature of the exposed data, this breach centers on customer financial and payment records rather than health or employment information. Still, individuals should not assume they are unaffected simply because they have not yet received a letter. Notification efforts sometimes take weeks to reach every impacted person.

What Information Was Potentially Exposed?

The Vermont Attorney General filing specifically names two categories of exposed data. Both categories relate directly to how customers pay for goods, which raises the stakes for anyone affected. Understanding what was taken helps clarify the specific risks involved.

  • Financial account codes
  • Credit and debit account information

Because payment card data was involved, affected individuals face a real risk of unauthorized charges. Criminals who obtain credit and debit account information often attempt quick fraudulent purchases before a victim notices. In addition, stolen financial account codes can sometimes be used to access or manipulate linked accounts directly.

Furthermore, this type of exposure often leads to secondary fraud attempts. For example, scammers frequently use stolen payment details to test smaller transactions first, then escalate to larger purchases if the fraud goes undetected. Consequently, affected individuals should treat any unfamiliar charge, no matter how small, as a potential warning sign.

What is the company doing?

High Mowing Organic Seeds took the step of formally notifying the Vermont Attorney General, which indicates the company has acknowledged the breach and is working through its legal obligations. This notification process typically follows an internal review confirming that customer data was compromised. As a result, affected customers should expect to receive, or may have already received, a direct notification letter.

Beyond the regulatory filing, the specific remediation steps taken by the company have not been publicly detailed. Many organizations in this situation work to secure their payment systems, coordinate with financial institutions, and monitor for further suspicious activity. Whether High Mowing Organic Seeds is offering credit monitoring or other protective services to affected customers has not been publicly disclosed at this time.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Affected individuals should request a copy of their credit report and review it carefully for unfamiliar accounts or inquiries. You can obtain a free report from each of the three major credit bureaus through AnnualCreditReport.com. Checking regularly makes it easier to catch fraudulent activity early.

Because financial account data was involved in this breach, ongoing vigilance matters more than a single check. Consider spacing out your free reports throughout the year so you have continuous visibility. If you notice anything suspicious, report it to the credit bureau immediately.

Consider a Fraud Alert or Credit Freeze

Given that credit and debit account information was exposed, placing a fraud alert on your credit file is a smart precaution. A fraud alert requires lenders to verify your identity before opening new credit in your name. This step is free and typically lasts for one year.

For stronger protection, you might also consider a credit freeze, which restricts access to your credit file entirely. This makes it significantly harder for identity thieves to open new accounts using your information. While a freeze requires a bit more effort to lift when you need credit, it offers the most robust defense available.

Watch for Phishing Attempts

After a breach involving financial data, scammers often follow up with phishing emails or texts pretending to be from the breached company or your bank. Because these messages can look convincing, never click links or provide personal details in response to unsolicited communication. Instead, contact the company or your bank directly using a verified phone number.

In addition, be cautious of any message urging immediate action or threatening account suspension. Legitimate companies rarely demand urgent payment information through email or text. If you receive a suspicious message referencing this breach, report it and delete it rather than responding.

Review Your Financial Statements Closely

Because payment account information was compromised, review your bank and credit card statements line by line for the coming months. Small, unfamiliar charges can indicate that criminals are testing whether your card details still work. Catching these early can prevent larger fraudulent transactions later.

If you spot any unauthorized activity, contact your bank or card issuer right away to dispute the charge and request a replacement card. Many financial institutions also offer free transaction alerts you can enable for added peace of mind. This proactive step gives you an extra layer of protection going forward.



More Information

Official data breach notification from Vermont Attorney General

Related Data Breaches

Check other recent data breach notifications →