MalwareRansomwareData ExfiltratedData EncryptedIDENTITY_BASICPIILowContained
Albertsons Companies, Inc.
bd_c85a389e62bca420 · schema v1 · pii pii-v1
Full breach record for Albertsons Companies, Inc. →Albertsons Companies, Inc. notified consumers of a data breach occurring December 22-24, 2022. An unauthorized third party gained access to systems, infected them with malware, and exfiltrated personal information including names and variable data. Albertsons engaged forensic investigators and law enforcement, and offered credit monitoring to affected individuals.
Vermont clock✗ VT AG >45 bday16 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_30bec6ca1499d08dCalifornia State AGfiled 2023-04-20(7d gap)Candidate
- bd_556f510ad121c832Washington State AGfiled 2023-04-20(7d gap)Verified
- bd_3be80bc4bbc05255Oregon State AGfiled 2023-04-21(8d gap)Verified
- bd_6df88f1931ce9002Montana State AGfiled 2023-04-21(8d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 8d gap
- bd_814c10e14c785e55Maine State AGfiled 2023-04-21(8d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-04-13-albertsons-companies-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 13, 2023
- Raw hash
- 4439198aea26f382180109f539fe2d9ce80eeab1d09c11874556fc8fd152150e
Reporting entity
- Name
- Albertsons Companies, Inc.norm: albertsons companies
- Domain
- albertsonscompanies.com
Victim entity
- Name
- Albertsons Companies, Inc.norm: albertsons companies
- Domain
- albertsonscompanies.com
Incident
- Discovered
- Dec 23, 2022
- Materiality determined
- —
- Notification sent
- Apr 21, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- contacted law enforcement
Compliance
- Time to disclose
- 16 weeks(111 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.