HackingVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICLowContained
Rite Aid Corporation
bd_cf24171c42f0d172 · schema v1 · pii pii-v1
Full breach record for Rite Aid Corporation →Rite Aid Corporation disclosed a data breach involving a vulnerability in a vendor partner's software exploited by an unknown third party. The incident occurred on May 27, 2023, and was discovered on May 31, 2023. Affected data included limited protected health information (names, DOB, addresses, prescription info) but no SSNs or financial data. Rite Aid installed a patch, notified regulators/law enforcement, and offered one year of identity monitoring via Kroll.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_4391b8c01e649ea8Washington State AGfiled 2023-07-19Verified
- bd_539cbd1ba62c4ed5HHS OCRfiled 2023-07-19Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-570564
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 19, 2023
- Raw hash
- be04c2b251d198be37276439659982bc8941d71f8553f66a739b6ce4c3b8eb3e
Reporting entity
- Name
- Rite Aid Corporationnorm: rite aid
- Domain
- riteaid.com
Victim entity
- Name
- Rite Aid Corporationnorm: rite aid
- Domain
- riteaid.com
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Reported to law enforcementReported to appropriate federal and state regulators
- Third party
- via vendor partner
- Initial access
- supply_chain
Compliance
- Time to disclose
- 7 weeks(49 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.