THE KROGER CO.
bd_6aaa39c445f321cc · schema v1 · pii pii-v1
Full breach record for THE KROGER CO. →7 incidents on fileKroger notified customers and employees of a data breach involving Accellion file transfer service. An unauthorized party exploited a vulnerability in Accellion's service to access files containing personal information, including names, contact details, dates of birth, Social Security numbers, and health/employment data. The incident occurred between Dec 24-29, 2020, and was discovered on Jan 23, 2021. Kroger discontinued Accellion services, reported to law enforcement, and offered two years of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 24, 2020
Begins
Jan 23, 2021
Discovered
Feb 19, 2021
Filed
vs. sector median
5 wks faster
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- HHS OCRbd_3e0294adc07168622021-02-19Verified by operator
- Washington State AGbd_be0af4b58344c9362021-02-19Verified
- Indiana State AGbd_d1b8496772be04482021-02-19Verified by operator
- Massachusetts State AGbd_df83dda5fb6772592021-02-19Verified by operator
Show 3 more filings ↓Show fewer ↑up to 26d gap
- Montana State AGbd_f38fff6774acc2fe2021-02-19Verified by operator
- South Carolina State AGbd_671cf941212846732021-02-22 · +3dVerified
- Montana State AGbd_ce7542d02671c8312021-03-17 · +26dVerified by operator
Filing propagation · 8 filings · 7 states
View merged incident ↗Pattern: first filing Feb 19 (OH), last Mar 17 (MT) — a 26-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.