Lowe's Companies, Inc.
bd_a69f411bf02abe4a · schema v1 · pii pii-v1
Full breach record for Lowe's Companies, Inc. →3 incidents on fileLowe's Companies, Inc. notified affected employees of unauthorized third-party access to Workday accounts on September 2, 2024. The attacker obtained usernames, passwords, and associated PII (name, address, DOB, email, phone, bank account). Lowe's reset passwords, implemented MFA, and offered 12 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 2, 2024
Discovered
Oct 9, 2024
Filed
vs. sector median
2 wks faster
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Indiana State AGbd_101665e6d03b6f362024-10-09Verified
- Maine State AGbd_e46fdb98575430442024-10-09Verified
- Massachusetts State AGbd_20610bb1de07b9e92024-10-12 · +3dVerified
- New Hampshire State AGbd_4c384f193d68f71b2024-10-15 · +6dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing Oct 9 (IN), last Oct 15 (NH) — a 6-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.