Norwex USA Data Breach: What Customers Should Know

Norwex USA, Inc., the direct-sales company known for its microfiber cleaning products, filed a data breach notification with the California Attorney General on December 23, 2024. The document submitted to regulators appears to be a scanned image rather than searchable text, so we were not able to pull specific details about how the breach happened, what information was involved, or how many people were affected directly from the filing itself. We want to be upfront about that gap rather than guess at facts we can’t confirm.

Because the notification doesn’t specify the number of people notified or their location, we can’t say with certainty who was affected beyond the fact that at least one California resident received notice, which is what triggered the state filing requirement in the first place. If you’re reading this because you received a letter from Norwex, that letter is the most reliable source of details specific to your situation, including what data was involved and any steps the company is asking you to take.

What data did Norwex say was exposed?
  • The specific categories of personal information involved were not disclosed in the portion of the filing we could read.
  • Breach notifications of this type typically involve some combination of names, contact details, and sometimes financial or identification numbers, but we can’t confirm which applies here.
  • Check your physical mailed letter from Norwex for the exact data elements listed, since notification letters are usually more detailed than the regulator filing summary.

Norwex’s public filing does not mention any free credit monitoring, identity theft protection, or other complimentary service being offered to affected individuals. If the letter you received includes such an offer, follow the instructions and any deadline printed directly on that letter, since we have no enrollment details to share from the regulatory copy.

How to protect yourself when the letter is short on details
  • Read your letter from Norwex closely for any specific data types listed — it may contain more than what’s in the public regulatory filing.
  • Watch your bank and credit card statements over the next several months for charges you don’t recognize, even small ones.
  • Place a free fraud alert or security freeze with the three major credit bureaus if the letter suggests any identification numbers may have been involved.
  • Be cautious of unexpected emails, texts, or calls claiming to be from Norwex asking you to verify account details — confirm through the company’s official customer service channels first.
  • Consider signing up for a service like Aura or LifeLock, which can alert you if your personal information starts showing up in places it shouldn’t.
  • Keep a copy of your notification letter in case you need to reference it later for a fraud dispute or credit bureau inquiry.

Norwex’s filing arrived with less public detail than many companies provide, a pattern we’ve also seen in other recent notices such as the Tecta America Corp breach filing. When more information becomes available or if Norwex issues an updated or clearer notice, we’ll revisit this page and add it.

Leave a Comment