HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICHEALTH_BASICCREDENTIALSLowContained
WALMART INC.
bd_fa957e6077a8e745 · schema v1 · pii pii-v1
Full breach record for WALMART INC. →Walmart notified Delaware AG of a breach affecting customer data via a supplier's compromised data hosting service. Unauthorized access occurred Jan 20, 2021; Walmart notified Feb 16, 2021. Data included names, DOB, addresses, and prescription details. Walmart's systems were not directly affected. One year of identity monitoring offered.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_3ab36a7f745a1a57Delaware State AGfiled 2021-03-05Candidate
- bd_ffcca6d35d3679dfHHS OCRfiled 2021-03-05Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2021/03/Template-Notification-Letter-Wyrick-Submission.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 5, 2021
- Raw hash
- 1f320d620ad890d00fcc8376474eaf2bd6f84741cb802a59fca768c0905bd591
Reporting entity
- Name
- WALMART INC.norm: walmart
- Domain
- walmart.com
Victim entity
- Name
- WALMART INC.norm: walmart
- Domain
- walmart.com
Incident
- Discovered
- Feb 16, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASICCREDENTIALS
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Initial access
- supply_chain
Compliance
- Time to disclose
- 17 days(17 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.