HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Rite Aid Online Store
bd_c72a26b421540a5e · schema v1 · pii pii-v1
Full breach record for Rite Aid Online Store →Rite Aid Online Store, Inc. disclosed a data breach affecting customers who entered payment card details on its e-commerce platform between January 30, 2017, and April 11, 2017. Unauthorized third parties accessed the platform and acquired personal information including names, addresses, emails, and payment card data (credit card numbers, expiration dates, CVVs). The company retained a security firm, worked with payment card brands, and offered one year of complimentary identity monitoring through Kroll.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_5e37c44a2a1b00ffWashington State AGfiled 2017-05-17Candidate
- bd_a26905d03e9aade7Montana State AGfiled 2017-05-17Verified
- bd_4007bd7c26da3131Oregon State AGfiled 2017-05-18(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-68929
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 17, 2017
- Raw hash
- 44e65ace9d01d6d5fa1cef8a2970b9f035815a862440b49c5395c8ed5ce91889
Reporting entity
- Name
- Rite Aid Online Storenorm: rite aid online store
Victim entity
- Name
- Rite Aid Online Storenorm: rite aid online store
Incident
- Discovered
- Apr 11, 2017
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.