W.W. GRAINGER, INC.
ent_019fa1f8624ea7c5b4a78aaecebea623
Disclosures
14
State AG · HHS OCR · 8 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
57,992
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- W.W. GRAINGER, INC.
- Normalized
- ww grainger— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300TWZSP6O1IH2V34
- SEC EDGAR CIK
- 0000277135
- Domain
- grainger.com
Disclosure history (14)newest first
- Massachusetts State AGas victim2018-04-20
W. W. Grainger, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-04-20. 448 Massachusetts residents were affected. The report records the breach type as electronic.
- Oregon State AGas victim2018-04-20
W.W. Grainger Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2018-04-20. The breach occurred during 9/26/2017 - 10/12/2017. The breach was discovered on 4/10/2018. 17,902 individuals were affected. Notice was sent on 4/18/2018.
- California State AGas victim2018-04-20
W.W. Grainger, Inc. notified customers that a third-party service provider, [24]7.ai, experienced a cyber incident between September 26, 2017, and October 12, 2017. The breach potentially exposed credit card numbers, security codes, expiration dates, names, and addresses of customers who used guest checkout on Grainger's website or app. Grainger was notified by [24]7.ai on April 10, 2018. The incident is resolved, and Grainger offered one year of identity monitoring through Kroll.
- New Hampshire State AGas victim2018-04-17
W.W. Grainger, Inc. notified the New Hampshire AG of a third-party breach involving chat provider [24]7.ai. Malware on [24]7.ai's systems potentially accessed credit card info and PII of customers who used guest checkout on Grainger.com between Sept 26 and Oct 12, 2017. Grainger was notified on April 10, 2018. 120 NH residents affected. Grainger offered credit monitoring and is reviewing vendor processes.
- Montana State AGas victim2018-04-17
Grainger, Inc. notified customers of a third-party data breach involving its online chat service provider, [24]7.ai. The incident occurred between September 26 and October 12, 2017, potentially exposing credit card numbers, security codes, expiration dates, names, and addresses of customers who used guest checkout. Grainger engaged forensic experts, notified law enforcement and credit card companies, and offered one year of identity monitoring via Kroll.
- South Carolina State AGas victim2017-09-22
W.W. Grainger, Inc. notified potentially affected individuals (employees/dependents) in South Carolina and other states that a team member's password-protected laptop was stolen on August 23, 2017. Data potentially included names, SSNs, DOBs, and benefits info. No evidence of unauthorized access was found. Grainger disabled credentials, initiated a wipe, engaged law enforcement, and offered 1 year of Kroll identity monitoring.
- Oregon State AGas victim2017-09-20
W.W. Grainger, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2017-09-20. The breach occurred during 8/23/2017 - 8/23/2017. The breach was discovered on 8/24/2017. 57,992 individuals were affected. Notice was sent on 9/18/2017.
- California State AGas victim2017-09-19
W.W. Grainger, Inc. reported the theft of an employee's laptop on August 23, 2017. The device contained personal information of current and former employees and their dependents, including names, contact information, Social Security numbers, dates of birth, and employee benefits information. Grainger disabled the employee's credentials and set the laptop to auto-wipe. No evidence of data access was found. The company offered one year of complimentary identity monitoring through Kroll.
- Massachusetts State AGas victim2017-09-19
W.W. Grainger Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-09-19. 401 Massachusetts residents were affected. The report records the breach type as electronic.
- ILLINOISHHS OCRas victim2017-09-18
W. W. Grainger, Inc. reported to HHS on 2017-09-18 a Theft affecting 1594 individuals. Breached information located on Laptop. An employee's laptop containing PHI (names, DOB, SSN, addresses) was stolen from an unlocked vehicle. WWGI implemented administrative safeguards and retrained staff.
- Washington State AGas victim2017-09-18
W.W. Grainger, Inc. reported the theft of a laptop containing employee PII (names, SSNs, contact info) on August 23, 2017. The incident affected 725 Washington residents. Grainger disabled credentials, engaged forensic counsel, and offered 12 months of credit monitoring.
- New Hampshire State AGas victim2017-09-18
W.W. Grainger, Inc. notified the NH Attorney General that a laptop containing personal information of approximately 119 current and former employees (NH residents) was stolen from an employee's vehicle on August 23, 2017. The data included names, contact information, Social Security numbers, and retirement benefits information. The laptop was password-protected and set to auto-wipe. No evidence of unauthorized access was found. Identity protection and credit monitoring services were offered.
- Montana State AGas victim2017-09-18
W.W. Grainger, Inc. notified Montana residents that a team member's password-protected laptop containing employee and dependent PII (including SSN, DOB, and benefits info) was stolen on August 23, 2017. No evidence of unauthorized access was found. Grainger disabled credentials, engaged law enforcement, and offered one year of Kroll identity monitoring.
- California State AGas victim2015-11-18
W.W. Grainger, Inc. identified a coding error in its mobile apps that resulted in the unsecured storage of usernames and passwords. The issue was discovered on October 27, 2015, and immediately fixed. No payment card or other personal information was affected. Passwords were reset as a precaution.
Supply-chain cascadesreviewed and confirmed
- W.W. GRAINGER, INC.’s filing is one of at least 5 in the [24]7.ai supply-chain incident (2018).