Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Rite Aid Corporation
bd_4ecedaca9ccb3324 · schema v1 · pii pii-v1
Full breach record for Rite Aid Corporation →Rite Aid Corporation reported that on June 6, 2024, an unknown third party impersonated an employee to compromise business credentials and access systems. The attacker acquired purchaser data (name, address, DOB, driver's license/government ID) for transactions between June 6, 2017, and July 30, 2018. No SSN, financial, or patient data was impacted. Rite Aid detected the incident within 12 hours, terminated access, and is offering identity monitoring via Kroll.
Leak gap clock✗ Leak >180d6 weeks discovery → filing
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_207d49685b6d18dfMontana State AGfiled 2024-07-15Candidate
- bd_889db9b4ae4e89f7Oregon State AGfiled 2024-07-15Verified
- bd_a417384d21d4f0c1Vermont State AGfiled 2024-07-15Verified
- bd_b4a3decb3cef6121Washington State AGfiled 2024-07-15Verified
Show 4 more filings ↓Show fewer ↑
- bd_c885a91972cf27f3Indiana State AGfiled 2024-07-15Verified
- bd_e9b3a4c075cb2fdaDelaware State AGfiled 2024-07-15Verified
- bd_eefa59da13cd3784New Hampshire State AGfiled 2024-07-15Verified
- bd_f56081669f275cdaMaine State AGfiled 2024-07-15Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-588589
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 15, 2024
- Raw hash
- 73c9aedde87d1848327266799575b2cb4ea4066f071c8a343a5b79af80b10e92
Reporting entity
- Name
- Rite Aid Corporationnorm: rite aid
- Domain
- riteaid.com
Victim entity
- Name
- Rite Aid Corporationnorm: rite aid
- Domain
- riteaid.com
Incident
- Discovered
- Jun 6, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1566 PhishingT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Reported to federal and state regulators
- Initial access
- phishing_link
Compliance
- Time to disclose
- 6 weeks(39 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.