HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
THE KROGER CO.
bd_6aaa39c445f321cc · schema v1 · pii pii-v1
Full breach record for THE KROGER CO. →The Kroger Co. reported a data security incident involving its third-party file transfer vendor, Accellion. An unauthorized actor exploited a vulnerability in Accellion's service to access files containing employee and patient information, including names, SSNs, and health data. The incident was discovered on January 23, 2021. Kroger discontinued the service, notified law enforcement, and provided two years of credit monitoring to affected individuals.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_3e0294adc0716862HHS OCRfiled 2021-02-19Verified
- bd_be0af4b58344c936Washington State AGfiled 2021-02-19Verified
- bd_671cf94121284673South Carolina State AGfiled 2021-02-22(3d gap)Verified
- bd_ce7542d02671c831Montana State AGfiled 2021-03-17(26d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-538150
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 19, 2021
- Raw hash
- 8f4aa1b5654673ceb02af5489a2528e1abae4722c121987217cd3ab6665f8c7c
Reporting entity
- Name
- THE KROGER CO.norm: the kroger
- Domain
- kroger.com
Victim entity
- Name
- THE KROGER CO.norm: the kroger
- Domain
- kroger.com
Incident
- Discovered
- Jan 23, 2021
- Materiality determined
- Feb 19, 2021
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Submitted breach notification to California Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 27 days(27 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.