HackingPhishingStolen CredentialsMulti-Stage ChainCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Rite Aid Corporation
bd_e9b3a4c075cb2fda · schema v1 · pii pii-v1
Full breach record for Rite Aid Corporation →Rite Aid Corporation disclosed a data breach where an unknown third party used phishing to steal business credentials and access systems. Data from purchases between June 2017 and July 2018 was compromised, including names, addresses, DOBs, and driver's licenses. No SSNs or financial data were impacted. Rite Aid reported to law enforcement and offered Kroll identity monitoring.
Leak gap clock✗ Leak >180d6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 9 about the same incident.View merged incident
A leak claim by cl0p about this victim predates this filing by 370 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_207d49685b6d18dfMontana State AGfiled 2024-07-15Candidate
- bd_4ecedaca9ccb3324California State AGfiled 2024-07-15Verified
- bd_889db9b4ae4e89f7Oregon State AGfiled 2024-07-15Verified
- bd_a417384d21d4f0c1Vermont State AGfiled 2024-07-15Verified
Show 4 more filings ↓Show fewer ↑
- bd_b4a3decb3cef6121Washington State AGfiled 2024-07-15Verified
- bd_c885a91972cf27f3Indiana State AGfiled 2024-07-15Verified
- bd_eefa59da13cd3784New Hampshire State AGfiled 2024-07-15Verified
- bd_f56081669f275cdaMaine State AGfiled 2024-07-15Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2024/07/Rite-Aid-Individual-Notice-Letter-Template.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 15, 2024
- Raw hash
- ab55885768a9cfa44eec28dccb1619a90659bc2bfa5428ac8816568be9ec0624
Reporting entity
- Name
- Rite Aid Corporationnorm: rite aid
- Domain
- riteaid.com
Victim entity
- Name
- Rite Aid Corporationnorm: rite aid
- Domain
- riteaid.com
Incident
- Discovered
- Jun 6, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- reported it to law enforcement, as well as federal and state regulators
- Initial access
- phishing_link
Compliance
- Time to disclose
- 6 weeks(39 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.