MalwareRansomwareStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICLowContained
Albertsons Companies, Inc.
bd_30bec6ca1499d08d · schema v1 · pii pii-v1
Full breach record for Albertsons Companies, Inc. →Albertsons Companies, Inc. reported a data security incident where an unauthorized third party gained access to systems and infected them with malware between December 22-24, 2022. The actor accessed and removed copies of data from file servers. Affected individuals may have had their names and other personal information exposed. Albertsons engaged forensics, contacted law enforcement, and offered credit monitoring.
California clockDiscovered Dec 23, 2022 → Notified Apr 21, 2023119d ✗ CA 60-day late17 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_556f510ad121c832Washington State AGfiled 2023-04-20Verified
- bd_3be80bc4bbc05255Oregon State AGfiled 2023-04-21(1d gap)Verified
- bd_6df88f1931ce9002Montana State AGfiled 2023-04-21(1d gap)Verified
- bd_814c10e14c785e55Maine State AGfiled 2023-04-21(1d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 7d gap
- bd_c85a389e62bca420Vermont State AGfiled 2023-04-13(7d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-565794
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 20, 2023
- Raw hash
- ced7504999f380a1377c7a56e7dd0c3d8dcde7005f10da0f0509b3f7dc4e184a
Reporting entity
- Name
- Albertsons Companies, Inc.norm: albertsons companies
- Domain
- albertsonscompanies.com
Victim entity
- Name
- Albertsons Companies, Inc.norm: albertsons companies
- Domain
- albertsonscompanies.com
Incident
- Discovered
- Dec 23, 2022
- Materiality determined
- —
- Notification sent
- Apr 21, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 17 weeks(118 days from discovery to filing)
- Compliance flags
- CA 60-day late · 119d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 23, 2022→ Notified: Apr 21, 2023119d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.