THE KROGER CO.
bd_3e0294adc0716862 · schema v1 · pii pii-v1
Full breach record for THE KROGER CO. →7 incidents on fileThe Kroger Co. reported to HHS on 2021-02-19 a Hacking/IT Incident affecting 1,474,284 individuals. The breach involved a business associate's cyberattack on a network server, exposing PHI including names, SSNs, DOBs, and treatment data. The entity provided credit monitoring and discontinued the compromised file transfer appliance.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Feb 19, 2021
Filed
No interval is drawn: no breach start or discovery date is on record for this filing.
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- California State AGbd_6aaa39c445f321cc2021-02-19Verified
- Washington State AGbd_be0af4b58344c9362021-02-19Verified
- Indiana State AGbd_d1b8496772be04482021-02-19Verified by operator
- Massachusetts State AGbd_df83dda5fb6772592021-02-19Verified by operator
Show 3 more filings ↓Show fewer ↑up to 26d gap
- Montana State AGbd_f38fff6774acc2fe2021-02-19Verified by operator
- South Carolina State AGbd_671cf941212846732021-02-22 · +3dVerified
- Montana State AGbd_ce7542d02671c8312021-03-17 · +26dVerified by operator
Filing propagation · 8 filings · 7 states
View merged incident ↗Pattern: first filing Feb 19 (CA), last Mar 17 (MT) — a 26-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.