Sam's Club
bd_3342767f104cb53f · schema v1 · pii pii-v1
Full breach record for Sam's Club →2 incidents on fileSam's Club notified the New Hampshire Attorney General on December 18, 2020, regarding a data security incident discovered on November 10, 2020. An unauthorized party used stolen login credentials (email and password) obtained from external sources to access member accounts and conduct fraudulent transactions involving Sam's Club Cash Rewards. Approximately one New Hampshire resident was affected. Sam's Club reset passwords, issued new membership numbers, placed holds on Cash Rewards, and offered one year of credit monitoring and identity protection services.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 10, 2020
Discovered
Dec 18, 2020
Filed
vs. sector median
2 wks faster
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- Indiana State AGbd_93a0a624f3fce5042020-12-18Verified
- New Hampshire State AGbd_5ae561446033257a2020-12-22 · +4dVerified
- Indiana State AGbd_30083d1eae0d677f2020-12-10 · +8dVerified
- Maine State AGbd_64d5d6cea3603f752020-12-10 · +8dCandidate
Show 2 more filings ↓Show fewer ↑up to 28d gap
- Montana State AGbd_ac1ed11c901502c42020-12-10 · +8dVerified
- Indiana State AGbd_5eb237bb8ca1e6fd2020-11-20 · +28dCandidate
Filing propagation · 7 filings · 4 states
View merged incident ↗Pattern: first filing Nov 20 (IN), last Dec 22 (NH) — a 32-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.