Sam's Club
bd_5ae561446033257a · schema v1 · pii pii-v1
Full breach record for Sam's Club →Sam's Club notified the New Hampshire Attorney General on December 18, 2020, of a data security incident discovered on November 19, 2020. An unauthorized party used stolen credentials (email and password) from an unrelated source to access member accounts. The attacker may have conducted fraudulent transactions involving Sam's Club Cash Rewards and accessed personal information including names, addresses, membership IDs, and partial payment card details. One New Hampshire resident was affected. Sam's Club reset passwords, implemented fraud defenses, and offered one year of credit monitoring.
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/sams-club-20201222.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 22, 2020
- Raw hash
- ab6f3812a7812aef9edce360ece220a0497049639a3bea0fbb0ef3206060210d
Reporting entity
- Name
- Sam's Clubnorm: sam s club
- Domain
- samsclub.com
Victim entity
- Name
- Sam's Clubnorm: sam s club
- Domain
- samsclub.com
Incident
- Discovered
- Nov 19, 2020
- Materiality determined
- —
- Notification sent
- Dec 18, 2020
- Affected individuals
- 1
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Department of Justice
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 5 weeks(33 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.