AccidentalMisdeliveryData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTPIIMediumContained
Lowe's Companies, Inc.
bd_59ff6c3249237e25 · schema v1 · pii pii-v1
Full breach record for Lowe's Companies, Inc. →Lowe's Companies, Inc. notified California AG that a third-party vendor's unsecured backup server containing personal information of current and former drivers and employees was accessible from the internet. Data exposure occurred between July 2013 and April 2014. Affected data included names, addresses, DOBs, SSNs, and driver's license numbers. Lowe's blocked access, engaged forensic experts, and provided one year of credit monitoring.
California clockDiscovered Apr 2, 2014 → Notified May 19, 201447d ✓ CA 60-day OK7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_79d65da91e512cc1New Hampshire State AGfiled 2014-05-19Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-45134
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 19, 2014
- Raw hash
- bed6fc0872b7a0e1eeb2e0157bc6d196b67873722f377054f69cbfae12fef335
Reporting entity
- Name
- Lowe's Companies, Inc.norm: lowe s companies
Victim entity
- Name
- Lowe's Companies, Inc.norm: lowe s companies
Incident
- Discovered
- Apr 2, 2014
- Materiality determined
- —
- Notification sent
- May 19, 2014
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- Partner
- Regulator citations
- Submitted breach notification to California Office of the Attorney General
- Third party
- via E-DriverFile
- Initial access
- supply_chain
Compliance
- Time to disclose
- 7 weeks(47 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 47d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Apr 2, 2014→ Notified: May 19, 201447d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.