Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedMulti-Stage ChainPIIIDENTITY_BASICHighContained
Rite Aid Corporation
bd_eefa59da13cd3784 · schema v1 · pii pii-v1
Full breach record for Rite Aid Corporation →Rite Aid Corporation notified New Hampshire and nationwide residents of a security incident where an unknown third party impersonated an employee to compromise business credentials and access systems on June 6, 2024. The breach affected approximately 2.2 million individuals nationwide, including 36,121 New Hampshire residents. Purchaser data associated with retail product purchases was acquired. Rite Aid detected the incident within 12 hours, terminated access, and engaged Kroll for identity monitoring services.
Leak gap clock✗ Leak >180d6 weeks discovery → filing
This filing is one of 9 about the same incident.View merged incident
A leak claim by cl0p about this victim predates this filing by 370 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_207d49685b6d18dfMontana State AGfiled 2024-07-15Candidate
- bd_4ecedaca9ccb3324California State AGfiled 2024-07-15Verified
- bd_889db9b4ae4e89f7Oregon State AGfiled 2024-07-15Verified
- bd_a417384d21d4f0c1Vermont State AGfiled 2024-07-15Verified
Show 4 more filings ↓Show fewer ↑
- bd_b4a3decb3cef6121Washington State AGfiled 2024-07-15Verified
- bd_c885a91972cf27f3Indiana State AGfiled 2024-07-15Verified
- bd_e9b3a4c075cb2fdaDelaware State AGfiled 2024-07-15Verified
- bd_f56081669f275cdaMaine State AGfiled 2024-07-15Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/rite-aid-20240715.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 15, 2024
- Raw hash
- 021cf60f2047055454fad2cc134f09a460c1e764ecbc5a61cec590d83baa3261
Reporting entity
- Name
- Rite Aid Corporationnorm: rite aid
- Domain
- riteaid.com
Victim entity
- Name
- Rite Aid Corporationnorm: rite aid
- Domain
- riteaid.com
Incident
- Discovered
- Jun 6, 2024
- Materiality determined
- Jun 17, 2024
- Notification sent
- Jul 15, 2024
- Affected individuals
- 2,200,000
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported to law enforcementReported to federal and state regulators
- Initial access
- phishing_link
Compliance
- Time to disclose
- 6 weeks(39 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.