Sam's Club
bd_5ae561446033257a · schema v1 · pii pii-v1
Full breach record for Sam's Club →2 incidents on fileSam's Club notified the NH Attorney General that an unauthorized party used stolen login credentials (email and password) to access member accounts on November 19, 2020. The credentials were stolen from external sources, not Sam's Club. The attacker may have accessed names, phone numbers, addresses, membership IDs, and partial payment card data, and conducted fraudulent Cash Rewards transactions. Approximately 1 New Hampshire resident was affected. Sam's Club reset passwords, implemented fraud defenses, and offered credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 19, 2020
Begins
Nov 19, 2020
Discovered
Dec 22, 2020
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- New Hampshire State AGbd_3342767f104cb53f2020-12-18 · +4dVerified
- Indiana State AGbd_93a0a624f3fce5042020-12-18 · +4dVerified
- Indiana State AGbd_30083d1eae0d677f2020-12-10 · +12dVerified
- Maine State AGbd_64d5d6cea3603f752020-12-10 · +12dCandidate
Show 2 more filings ↓Show fewer ↑up to 32d gap
- Montana State AGbd_ac1ed11c901502c42020-12-10 · +12dVerified
- Indiana State AGbd_5eb237bb8ca1e6fd2020-11-20 · +32dCandidate
Filing propagation · 7 filings · 4 states
View merged incident ↗Pattern: first filing Nov 20 (IN), last Dec 22 (NH) — a 32-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.