Sam's Club
bd_64d5d6cea3603f75 · schema v1 · pii pii-v1
Full breach record for Sam's Club →2 incidents on fileSam's Club experienced an account takeover incident via credential stuffing, where an unauthorized third party gained access to customer accounts. The breach resulted in the exposure of financial account numbers or credit/debit card numbers, along with their security codes or PINs. Affected individuals were offered 12 months of identity theft monitoring and restoration services through Experian.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 10, 2020
Begins
Nov 10, 2020
Discovered
Dec 10, 2020
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- Indiana State AGbd_30083d1eae0d677f2020-12-10Verified
- Montana State AGbd_ac1ed11c901502c42020-12-10Verified
- New Hampshire State AGbd_3342767f104cb53f2020-12-18 · +8dVerified
- Indiana State AGbd_93a0a624f3fce5042020-12-18 · +8dVerified
Show 2 more filings ↓Show fewer ↑up to 20d gap
- New Hampshire State AGbd_5ae561446033257a2020-12-22 · +12dVerified
- Indiana State AGbd_5eb237bb8ca1e6fd2020-11-20 · +20dCandidate
Filing propagation · 7 filings · 4 states
View merged incident ↗Pattern: first filing Nov 20 (IN), last Dec 22 (NH) — a 32-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.