HackingData MishandlingSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
WALMART INC.
bd_3ab36a7f745a1a57 · schema v1 · pii pii-v1
Full breach record for WALMART INC. →Walmart Inc. issued a Delaware state AG breach notification regarding a third-party data hosting service compromise. An unauthorized party accessed records on January 20, 2021, and Walmart was notified on February 16, 2021. Walmart's own systems were not affected. Affected data included names, addresses, DOB, phone numbers, and prescription/medication details. Walmart offered one year of identity monitoring services.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_fa957e6077a8e745Delaware State AGfiled 2021-03-05Verified
- bd_ffcca6d35d3679dfHHS OCRfiled 2021-03-05Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2021/03/Template-Notification-Letter-Wyrick-Submission.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 5, 2021
- Raw hash
- 33ee85d5eba2d027e81fef476a59fcd2306c029ac12748b6cd213932bab87c40
Reporting entity
- Name
- WALMART INC.norm: walmart
- Domain
- walmart.com
Victim entity
- Name
- WALMART INC.norm: walmart
- Domain
- walmart.com
Incident
- Discovered
- Feb 16, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Initial access
- supply_chain
Compliance
- Time to disclose
- 17 days(17 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.