THE KROGER CO.
bd_f38fff6774acc2fe · schema v1 · pii pii-v1
Full breach record for THE KROGER CO. →7 incidents on fileThe Kroger Co. notified Montana residents of a data breach involving Accellion, a third-party file transfer service. An unauthorized party exploited a vulnerability in Accellion's service on January 23, 2021, accessing files containing employee and patient data. Impacted data included names, contact info, SSNs, DOBs, and health/employment records. Kroger discontinued the service, notified law enforcement, and offered 2 years of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 23, 2021
Begins
Jan 23, 2021
Discovered
Feb 19, 2021
Filed
vs. sector median
5 wks faster
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- HHS OCRbd_3e0294adc07168622021-02-19Verified by operator
- California State AGbd_6aaa39c445f321cc2021-02-19Verified
- Washington State AGbd_be0af4b58344c9362021-02-19Verified
- Indiana State AGbd_d1b8496772be04482021-02-19Verified by operator
Show 3 more filings ↓Show fewer ↑up to 26d gap
- Massachusetts State AGbd_df83dda5fb6772592021-02-19Verified by operator
- South Carolina State AGbd_671cf941212846732021-02-22 · +3dVerified
- Montana State AGbd_ce7542d02671c8312021-03-17 · +26dVerified by operator
Filing propagation · 8 filings · 7 states
View merged incident ↗Pattern: first filing Feb 19 (OH), last Mar 17 (MT) — a 26-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.