HackingStolen CredentialsTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Rite Aid Corporation
bd_a417384d21d4f0c1 · schema v1 · pii pii-v1
Full breach record for Rite Aid Corporation →Rite Aid notified consumers in Vermont of a data breach where an unknown third party compromised business credentials by impersonating an employee. The incident, occurring between June 2017 and July 2018, exposed names, addresses, dates of birth, and driver's license numbers. Rite Aid reported the incident to law enforcement and regulators, engaged Kroll for identity monitoring services, and implemented additional security measures.
Leak gap clock✗ Leak >180d6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 9 about the same incident.View merged incident
A leak claim by cl0p about this victim predates this filing by 370 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_207d49685b6d18dfMontana State AGfiled 2024-07-15Candidate
- bd_4ecedaca9ccb3324California State AGfiled 2024-07-15Verified
- bd_889db9b4ae4e89f7Oregon State AGfiled 2024-07-15Verified
- bd_b4a3decb3cef6121Washington State AGfiled 2024-07-15Verified
Show 4 more filings ↓Show fewer ↑
- bd_c885a91972cf27f3Indiana State AGfiled 2024-07-15Verified
- bd_e9b3a4c075cb2fdaDelaware State AGfiled 2024-07-15Verified
- bd_eefa59da13cd3784New Hampshire State AGfiled 2024-07-15Verified
- bd_f56081669f275cdaMaine State AGfiled 2024-07-15Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-07-15-rite-aid-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 15, 2024
- Raw hash
- 1d13f6c051629e7cc28f2bdbbbd4367dea3cbde8d389aab0120ed2d89e53b442
Reporting entity
- Name
- Rite Aid Corporationnorm: rite aid
- Domain
- riteaid.com
Victim entity
- Name
- Rite Aid Corporationnorm: rite aid
- Domain
- riteaid.com
Incident
- Discovered
- Jun 6, 2024
- Materiality determined
- —
- Notification sent
- Jul 15, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported to federal and state regulators
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 6 weeks(39 days from discovery to filing)
- Compliance flags
- Leak >180dVT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.