Sam's Club
bd_7d21906a2e56f1f3 · schema v1 · pii pii-v1
Full breach record for Sam's Club →2 incidents on fileSam's Club notified Washington AG of a cyberattack where unauthorized parties used stolen credentials to access member accounts and conduct fraudulent transactions involving Cash Rewards. Approximately 771 Washington residents were affected. Data accessed included names, contact info, and financial account details. Sam's Club reset passwords, issued new membership numbers, and offered credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 17, 2020
Begins
Sep 24, 2020
Discovered
Oct 21, 2020
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- California State AGbd_08ecc982b2d6f96d2020-10-21Verified
- Indiana State AGbd_141e5312d6ac324c2020-10-21Verified
- Massachusetts State AGbd_1baae9e84867a9c82020-10-21Verified
- Montana State AGbd_4f6b4c84c24d1c432020-10-21Candidate
Show 5 more filings ↓Show fewer ↑up to 8d gap
- Oregon State AGbd_7843c49c2426c7f02020-10-21Verified
- Delaware State AGbd_b5f7ad4d0323fe252020-10-21Verified
- Maine State AGbd_9d8b96b56225f1ab2020-10-22 · +1dVerified
- New Hampshire State AGbd_cd60e531f69a19792020-10-26 · +5dVerified
- South Carolina State AGbd_aa274a38b4804ce32020-10-29 · +8dVerified
Filing propagation · 10 filings · 10 states
View merged incident ↗Pattern: first filing Oct 21 (CA), last Oct 29 (SC) — a 8-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.