THE KROGER CO.
bd_be0af4b58344c936 · schema v1 · pii pii-v1
Full breach record for THE KROGER CO. →7 incidents on fileThe Kroger Co. reported a data security incident involving its third-party file transfer vendor, Accellion. An unauthorized party exploited a vulnerability in Accellion's service between Dec 24-29, 2020. Kroger discovered the impact on Jan 23, 2021. Impacted data included employee PII (SSN, DOB, salary) and patient PHI (prescriptions, medical history). 153,800 Washington residents were notified on Feb 19, 2021, and offered 2 years of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 24, 2020
Begins
Jan 23, 2021
Discovered
Feb 19, 2021
Filed
vs. sector median
5 wks faster
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- HHS OCRbd_3e0294adc07168622021-02-19Verified by operator
- California State AGbd_6aaa39c445f321cc2021-02-19Verified
- Indiana State AGbd_d1b8496772be04482021-02-19Verified by operator
- Massachusetts State AGbd_df83dda5fb6772592021-02-19Verified by operator
Show 3 more filings ↓Show fewer ↑up to 26d gap
- Montana State AGbd_f38fff6774acc2fe2021-02-19Verified by operator
- South Carolina State AGbd_671cf941212846732021-02-22 · +3dVerified
- Montana State AGbd_ce7542d02671c8312021-03-17 · +26dVerified by operator
Filing propagation · 8 filings · 7 states
View merged incident ↗Pattern: first filing Feb 19 (OH), last Mar 17 (MT) — a 26-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.