AccidentalMisconfigurationCustomer Data InvolvedIDENTITY_BASICHEALTH_BASICLowContained
Walgreen Co.
bd_82bc5a0283667f8d · schema v1 · pii pii-v1
Full breach record for Walgreen Co. →Walgreen Co. disclosed a January 2020 incident where an internal application error in its mobile app allowed customers to view other customers' secure messages. Affected data included names, prescription numbers, drug names, store numbers, and shipping addresses. No financial or SSN data was involved. Walgreens disabled the feature and implemented a technical correction.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_61bdc54c0c5fcd19HHS OCRfiled 2020-02-28Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-187787
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 28, 2020
- Raw hash
- 776a6cea06d75c8d1ff259ea7b358b20d877629278c9d8ae2f351d6bedd4736e
Reporting entity
- Name
- Walgreen Co.norm: walgreen
- Domain
- walgreens.com
Victim entity
- Name
- Walgreen Co.norm: walgreen
- Domain
- walgreens.com
Incident
- Discovered
- Jan 15, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1530 Data from Cloud Storage Object
Compliance
- Time to disclose
- 6 weeks(44 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.