THE KROGER CO.
ent_019e0a6f0d444b5acdf4eff9ff51e882
Disclosures
18
HHS OCR · State AG · 10 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
1,474,284
nationwide · HHS OCR OH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- THE KROGER CO.
- Normalized
- the kroger— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 6CPEOKI6OYJ13Q6O7870
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- kroger.com
Disclosure history (18)newest first
- OHIOHHS OCRas victim2021-11-12
The Kroger Company reported to HHS on 2021-11-12 a Theft affecting 2686 individuals. Breached information located on Laptop, Paper/Films. A journal containing PHI (names, medical record numbers, medications) was stolen. The entity notified HHS, individuals, and media, and sanctioned/retrained the responsible employee.
- Montana State AGas victim2021-03-17
Western Union notified Montana AG that Kroger Company's third-party file transfer vendor (Accellion) was compromised. Unauthorized access occurred Dec 24-29, 2020; discovered Jan 23, 2021. Data exfiltrated included names, addresses, phone numbers, driver's licenses, and SSNs. 8 Montana residents affected. Notifications mailed March 17, 2021.
- South Carolina State AGas victim2021-02-22
The Kroger Co. notified South Carolina residents of a data breach involving Accellion, a third-party secure file transfer service. An unauthorized party exploited a vulnerability in Accellion's service to access files containing associate benefit information, including names, contact info, DOB, and health plan details. Kroger discontinued the service, reported to law enforcement, and offered 2 years of credit monitoring.
- OHIOHHS OCRas victim2021-02-19
The Kroger Co. reported to HHS on 2021-02-19 a Hacking/IT Incident affecting 1,474,284 individuals. The breach involved a business associate's cyberattack on a network server, exposing PHI including names, SSNs, DOBs, and treatment data. The entity provided credit monitoring and discontinued the compromised file transfer appliance.
- California State AGas victim2021-02-19
Kroger notified customers and employees of a data breach involving Accellion file transfer service. An unauthorized party exploited a vulnerability in Accellion's service to access files containing personal information, including names, contact details, dates of birth, Social Security numbers, and health/employment data. The incident occurred between Dec 24-29, 2020, and was discovered on Jan 23, 2021. Kroger discontinued Accellion services, reported to law enforcement, and offered two years of credit monitoring.
- Washington State AGas victim2021-02-19
The Kroger Co. reported a data security incident involving its third-party file transfer vendor, Accellion. An unauthorized party exploited a vulnerability in Accellion's service between Dec 24-29, 2020. Kroger discovered the impact on Jan 23, 2021. Impacted data included employee PII (SSN, DOB, salary) and patient PHI (prescriptions, medical history). 153,800 Washington residents were notified on Feb 19, 2021, and offered 2 years of credit monitoring.
- Indiana State AGas victim2021-02-19
The Kroger Co and its affiliated Companies reported a data breach to the Indiana Attorney General. The breach occurred on 2020-12-24 and was reported on 2021-02-19. 208,100 Indiana residents were affected. 1,040,000 individuals affected in total.
- Massachusetts State AGas victim2021-02-19
The Kroger Co. and its affiliated companies reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-02-19. 300 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2021-02-19
The Kroger Co. notified Montana residents of a data breach involving Accellion, a third-party file transfer service. An unauthorized party exploited a vulnerability in Accellion's service on January 23, 2021, accessing files containing employee and patient data. Impacted data included names, contact info, SSNs, DOBs, and health/employment records. Kroger discontinued the service, notified law enforcement, and offered 2 years of credit monitoring.
- Illinois State AGas victim2021-01-01
THE KROGER, CO filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-056). The register records the breach as discovered on December 24, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- OHIOHHS OCRas victim2020-06-18
The Kroger Company reported to HHS on 2020-06-18 a Unauthorized Access/Disclosure affecting 132,258 individuals. Breached information located on Network Server. PHI included names, phone numbers, email addresses, birthdates, diagnoses, and treatment information.
- OHIOHHS OCRas victim2019-10-25
The Kroger Co. reported to HHS on 2019-10-25 a Loss affecting 4812 individuals. Breached information located on Paper/Films. A shipping service lost a box of patient records containing PHI including names, prescription numbers, and health insurance information.
- OHIOHHS OCRas victim2019-10-25
The Kroger Co. reported to HHS on 2019-10-25 a Loss affecting 2752 individuals. Breached information located on Paper/Films. An employee improperly disposed of PHI including names, DOBs, addresses, diagnoses, and medication info. The CE sanctioned the employee and re-trained staff on disposal and retention policies.
- Oregon State AGas victim2016-05-27
The Kroger Co reported a data breach to the Oregon Attorney General. The breach was reported on 2016-05-27. The breach occurred during 1/31/2016. The breach was discovered on 4/27/2016. Notice was sent on 5/3/20165/5/20165/25/2016.
- Massachusetts State AGas victim2016-05-26
The Kroger Co reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-05-26. 5 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2016-05-25
Kroger Co. notified Montana and other state residents of a data breach involving Equifax W-2Express accounts. Attackers used stolen SSNs and DOBs obtained via phishing to access W-2 forms of current and former associates. Discovery was April 27, 2016. Kroger engaged FBI/IRS and provided credit monitoring.
- New Hampshire State AGas victim2016-05-25
The Kroger Co. notified the NH AG of a data security incident involving employee W-2 data. Unknown individuals accessed Equifax W-2Express using default login info based on SSNs and DOBs obtained from a prior breach. Incident discovered April 27, 2016. Notification sent May 25, 2016. Approx 2 NH residents affected. Data included names, addresses, SSNs, income info. Identity monitoring offered.
- OHIOHHS OCRas victim2014-02-26
The Kroger Co. reported to HHS on 2014-02-26 a breach of type 'Other' affecting 504 individuals. Breached information was located on Electronic Medical Record.
Supply-chain cascadesreviewed and confirmed
- THE KROGER CO.’s filing is one of at least 12 in the Accellion supply-chain incident (2021).