Lowe's Companies, Inc.
ent_019e215b90500890e0915c9d29f1a440
Disclosures
8
State AG · 6 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
944
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Lowe's Companies, Inc.
- Normalized
- lowe s companies— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- WAFCR4OKGSC504WU3E95
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (8)newest first
- New Hampshire State AGas victim2024-10-15
Lowe’s Companies, Inc. notified the NH Attorney General of a phishing incident where unauthorized third-party access was gained to employee Workday accounts via fraudulent Google ads. Discovered Sept 2, 2024, the incident affected 5 NH residents, exposing usernames, passwords, and associated PII. Lowe’s reset passwords, disabled external Workday access, and is implementing MFA. Credit monitoring is offered.
- Massachusetts State AGas victim2024-10-12
Lowe's Companies, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-10-12. 10 Massachusetts residents were affected.
- Indiana State AGas victim2024-10-09
Lowe's Companies Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2024-09-02 and was reported on 2024-10-09. 21 Indiana residents were affected. 944 individuals affected in total.
- Montana State AGas victim2024-10-09
Lowe's Companies, Inc. notified affected employees of unauthorized third-party access to Workday accounts on September 2, 2024. The attacker obtained usernames, passwords, and associated PII (name, address, DOB, email, phone, bank account). Lowe's reset passwords, implemented MFA, and offered 12 months of credit monitoring.
- Maine State AGas victim2024-10-09
Lowe's Companies, Inc. reported unauthorized third-party access to employee Workday accounts on September 2, 2024. The attacker obtained usernames, passwords, and associated PII (name, address, DOB, email, phone, bank account). 944 individuals affected; 6 in Maine. Notification sent October 9, 2024. Remediation included password resets and MFA implementation.
- Massachusetts State AGas victim2014-05-27
Lowe's Companies Inc reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2014-05-27. 339 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2014-05-19
Lowe's Companies, Inc. notified the California Attorney General that a third-party vendor (E-DriverFile) unintentionally backed up personal information to an unsecured server accessible from the Internet. The data, which included names, addresses, dates of birth, Social Security numbers, and driver's license numbers for current and former drivers and employees, may have been accessed between July 2013 and April 2014. The vendor blocked access to the server and retained security experts. Lowe's is offering one year of credit protection services.
- New Hampshire State AGas victim2014-05-19
Lowe's Companies, Inc. notified the NH Attorney General that its third-party vendor, SafetyFirst, unintentionally backed up driver and employee data (including SSNs and driver's licenses) to an unsecured internet-accessible server. Access occurred between July 2013 and April 2014. 281 NH residents affected. No evidence of misuse. Credit monitoring offered.