DisclosureLens
HackingRetail & ConsumerRetailStolen CredentialsTargetedIdentity (basic)Government IDMediumContained

Rite Aid Corporation

bd_a417384d21d4f0c1 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jun 6, 2024

Filed

Jul 15, 2024

To disclose

6 weeks

Affected

Not disclosed

Linked

13 filings

Confidence

66%
Full breach record for Rite Aid Corporation10 incidents on file

Rite Aid notified consumers in Vermont of a data breach where an unknown third party compromised business credentials by impersonating an employee. The incident, occurring between June 2017 and July 2018, exposed names, addresses, dates of birth, and driver's license numbers. Rite Aid reported the incident to law enforcement and regulators, engaged Kroll for identity monitoring services, and implemented additional security measures.

Leak gap clock Leak >180d6 weeks discovery → filing
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

undetected · 2557 days
discovery → filing · 6 weeks / 39 days

Jun 6, 2017

Begins

Jun 6, 2024

Discovered

Jul 15, 2024

Filed

vs. sector median

2 wks faster

This filing is one of 13 about the same incident.View merged incident
A leak claim by cl0p about this victim predates this filing by 370 days.View originating leak claim

Linked disclosures

Why this link?

Regulatory filings (10) · sorted by filing gap

Show 6 more filings

Showing first 10 of 12 linked disclosures.

Filing propagation · 11 filings · 11 states

View merged incident ↗
Montana State AGJul 15 · first
California State AGJul 15 · first
Massachusetts State AGJul 15 · first
Oregon State AGJul 15 · first
Washington State AGJul 15 · first
Indiana State AGJul 15 · first
Delaware State AGJul 15 · first
New Hampshire State AGJul 15 · first
Maine State AGJul 15 · first
Vermont State AGJul 15 · first · this page

Cascade drawn from the first 10 linked disclosures of 12 — the full spread may be wider.

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.