DisclosureLens
HackingRetail & ConsumerHealthcareRetailVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedEmployee Data InvolvedFinancialHealth (basic)Identity (basic)Government IDPHICriticalContained

THE KROGER CO.

bd_be0af4b58344c936 · schema v1 · pii pii-v1

Severity

Critical

Discovered

Jan 23, 2021

Filed

Feb 19, 2021

To disclose

27 days

Affected

153,800state residents only

Linked

8 filings

Confidence

71%
Full breach record for THE KROGER CO. →7 incidents on file

The Kroger Co. reported a data security incident involving its third-party file transfer vendor, Accellion. An unauthorized party exploited a vulnerability in Accellion's service between Dec 24-29, 2020. Kroger discovered the impact on Jan 23, 2021. Impacted data included employee PII (SSN, DOB, salary) and patient PHI (prescriptions, medical history). 153,800 Washington residents were notified on Feb 19, 2021, and offered 2 years of credit monitoring.

Washington clock✓ WA AG ≤30d27 days discovery → filing
⚠ AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 30 days
discovery → filing · 27 days

Dec 24, 2020

Begins

Jan 23, 2021

Discovered

Feb 19, 2021

Filed

vs. sector median

5 wks faster

This filing is one of 8 filings about the same incident.View merged incident
Part of Accellion supply-chain incident (2021) — a supply-chain cascade affecting multiple organizations.View cascade →

Linked disclosures

Why this link?

Regulatory filings (7) · sorted by filing gap

Show 3 more filings ↓up to 26d gap

Filing propagation · 8 filings · 7 states

View merged incident ↗
HHS OCRFeb 19 · first
California State AGFeb 19 · first
Indiana State AGFeb 19 · first
Massachusetts State AGFeb 19 · first
Montana State AGFeb 19 · first
Washington State AGFeb 19 · first · this page

Pattern: first filing Feb 19 (OH), last Mar 17 (MT) — a 26-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.