THE KROGER CO.
ent_019e0a6f0d444b5acdf4eff9ff51e882
Disclosures
9
SEC 10-K Item 1C · HHS OCR · State AG · 7 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
1,474,284
nationwide · HHS OCR OH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- THE KROGER CO.
- Normalized
- the kroger— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 6CPEOKI6OYJ13Q6O7870
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- kroger.com
Disclosure history (9)newest first
- FEDERALSEC 10-K Item 1Cas victim2026-03-31
The Kroger Co. filed its 10-K Item 1C disclosing its cybersecurity risk management and governance framework. The company states it is not aware of any material cybersecurity threats that have materially affected its business, financial condition, or results of operations in the last three years. The filing details the Kroger Cybersecurity Risk Management (CRM) program, Third-Party Cybersecurity Risk Management (TPCRM) program, and Cyber Incident Response Plan (IR Plan). Governance is overseen by the Audit Committee with quarterly reporting from the CDO and CISO.
- OHHHS OCRas victim2021-11-12
The Kroger Company reported to HHS on 2021-11-12 a Theft affecting 2686 individuals. Breached information located on Laptop, Paper/Films. A journal containing PHI (names, medical record numbers, medications) was stolen. The entity notified HHS, individuals, and media, and sanctioned/retrained the responsible employee.
- 🦬Montana State AGas victim2021-03-17
Kroger Company reported a data breach to the Montana Attorney General. The breach was reported on 2021-03-17. The breach occurred from 12/24/2020 to 12/29/2020. 8 Montana residents were affected.
- 🌴South Carolina State AGas victim2021-02-22
The Kroger Co. notified South Carolina residents of a data breach involving Accellion, a third-party secure file transfer service. An unauthorized party exploited a vulnerability in Accellion's service to access files containing associate benefit information, including names, contact info, DOB, and health plan details. Kroger discontinued the service, reported to law enforcement, and offered 2 years of credit monitoring.
- OHHHS OCRas victim2021-02-19
The Kroger Co. reported to HHS on 2021-02-19 a Hacking/IT Incident affecting 1,474,284 individuals. The breach involved a business associate's cyberattack on a network server, exposing PHI including names, SSNs, DOBs, and treatment data. The entity provided credit monitoring and discontinued the compromised file transfer appliance.
- 🐻California State AGas victim2021-02-19
The Kroger Co. reported a data security incident involving its third-party file transfer vendor, Accellion. An unauthorized actor exploited a vulnerability in Accellion's service to access files containing employee and patient information, including names, SSNs, and health data. The incident was discovered on January 23, 2021. Kroger discontinued the service, notified law enforcement, and provided two years of credit monitoring to affected individuals.
- 🌲Washington State AGas victim2021-02-19
The Kroger Co., a business sector entity reported a malware incident to the Washington Attorney General. The organization became aware of the incident on 2021-01-23 and filed notice on 2021-02-19. 153,800 Washington residents were affected. 27 days elapsed between awareness and notification. 30 days to identify the breach. 0 days to contain the breach.
- 🦫Oregon State AGas victim2016-05-27
The Kroger Co reported a data breach to the Oregon Attorney General. The breach was reported on 2016-05-27. The breach occurred during 1/31/2016. The breach was discovered on 4/27/2016. Notice was sent on 5/3/20165/5/20165/25/2016.
- 🦬Montana State AGas victim2016-05-25
Kroger Co. reported a data breach to the Montana Attorney General. The breach was reported on 2016-05-25. The breach occurred from 1/20/2016 to 4/27/2016. 20 Montana residents were affected.