W.W. GRAINGER, INC.
bd_c0b4f1c05e8f1a1b · schema v1 · pii pii-v1
Full breach record for W.W. GRAINGER, INC. →3 incidents on fileW.W. Grainger, Inc. notified the New Hampshire AG of a third-party breach involving chat provider [24]7.ai. Malware on [24]7.ai's systems potentially accessed credit card info and PII of customers who used guest checkout on Grainger.com between Sept 26 and Oct 12, 2017. Grainger was notified on April 10, 2018. 120 NH residents affected. Grainger offered credit monitoring and is reviewing vendor processes.
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 26, 2017
Begins
Apr 10, 2018
Discovered
Apr 17, 2018
Filed
vs. sector median
7 wks faster
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Montana State AGbd_e6ca845903bcf77c2018-04-17Candidate
- Massachusetts State AGbd_6caecc5f9930ca1a2018-04-20 · +3dVerified
- Oregon State AGbd_6cb01f45a52b50042018-04-20 · +3dVerified by operator
- California State AGbd_a12fd61c534fd6ab2018-04-20 · +3dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.