Sam's Club
ent_28e40b0c96bb435e27733263
Disclosures
17
State AG · 10 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
285,885
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Sam's Club
- Normalized
- sam s club— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- samsclub.com
Disclosure history (17)newest first
- New Hampshire State AGas victim2020-12-22
Sam's Club notified the NH Attorney General that an unauthorized party used stolen login credentials (email and password) to access member accounts on November 19, 2020. The credentials were stolen from external sources, not Sam's Club. The attacker may have accessed names, phone numbers, addresses, membership IDs, and partial payment card data, and conducted fraudulent Cash Rewards transactions. Approximately 1 New Hampshire resident was affected. Sam's Club reset passwords, implemented fraud defenses, and offered credit monitoring.
- New Hampshire State AGas victim2020-12-18
Sam's Club notified the New Hampshire Attorney General on December 18, 2020, regarding a data security incident discovered on November 10, 2020. An unauthorized party used stolen login credentials (email and password) obtained from external sources to access member accounts and conduct fraudulent transactions involving Sam's Club Cash Rewards. Approximately one New Hampshire resident was affected. Sam's Club reset passwords, issued new membership numbers, placed holds on Cash Rewards, and offered one year of credit monitoring and identity protection services.
- Indiana State AGas victim2020-12-18
Sam's West, Inc. dba Sam's Club reported a data breach to the Indiana Attorney General. The breach occurred on 2020-11-19 and was reported on 2020-12-18. 4 Indiana residents were affected. 137 individuals affected in total.
- Indiana State AGas victim2020-12-10
Sam's West, Inc. dba Sam's Club reported a data breach to the Indiana Attorney General. The breach occurred on 2020-11-10 and was reported on 2020-12-10. 8 Indiana residents were affected. 418 individuals affected in total.
- Maine State AGas victim2020-12-10
Sam's Club experienced an account takeover incident via credential stuffing, where an unauthorized third party gained access to customer accounts. The breach resulted in the exposure of financial account numbers or credit/debit card numbers, along with their security codes or PINs. Affected individuals were offered 12 months of identity theft monitoring and restoration services through Experian.
- Montana State AGas victim2020-12-10
Sam's Club notified Montana residents that in mid-November 2020, an unauthorized party used stolen login credentials (likely from a third-party breach) to access member accounts. The incident may have exposed names, contact info, membership details, and partial payment card data. Sam's Club reset passwords, issued new membership numbers, and provided one year of free credit monitoring via Experian.
- Indiana State AGas victim2020-11-20
Sam's West, Inc. dba Sam's Club reported a data breach to the Indiana Attorney General. The breach occurred on 2020-10-20 and was reported on 2020-11-20. 4 Indiana residents were affected. 156 individuals affected in total.
- South Carolina State AGas victim2020-10-29
Sam's Club notified members in October 2020 that unauthorized parties used stolen login credentials (likely from a third-party source) to access accounts in mid-September 2020. Access may have included names, addresses, membership IDs, and Cash Rewards balances. Sam's Club reset passwords, issued new membership numbers, held Cash Rewards balances, and offered one year of free identity protection via Experian.
- New Hampshire State AGas victim2020-10-26
Sam's Club notified the New Hampshire DOJ on October 22, 2020, of a breach discovered September 24, 2020. An unauthorized party used stolen credentials (email/password) from an unrelated source to access member accounts and conduct fraudulent transactions involving Sam's Club Cash Rewards. Approximately 717 New Hampshire residents were affected. Data accessed included names, addresses, phone numbers, and Cash Rewards balances. Sam's Club reset passwords, issued new membership numbers, placed holds on rewards, and offered one year of credit monitoring.
- Maine State AGas victim2020-10-22
Sam's Club reported a data breach occurring between September 17 and 24, 2020, discovered on September 24, 2020. The incident involved account takeover via credential stuffing, affecting 285,885 individuals, including 1,038 in Maine. Compromised data included names and financial account numbers (credit/debit card numbers with security codes/PINs). Sam's Club notified consumers in writing on October 21, 2020, and offered 12 months of credit monitoring and ID restoration services through Experian.
- California State AGas victim2020-10-21
Sam's Club reported a data security breach to the California Attorney General. The incident occurred on September 24, 2020. The provided source document contains only the filing metadata and an empty attachment placeholder; no narrative details regarding the nature of the breach, data types affected, or response actions are available in the text.
- Indiana State AGas victim2020-10-21
Sam's West Inc dba Sam's Club reported a data breach to the Indiana Attorney General. The breach occurred on 2020-09-17 and was reported on 2020-10-21. 7,120 Indiana residents were affected. 285,885 individuals affected in total.
- Massachusetts State AGas victim2020-10-21
Sam's West, Inc. dba Sam's Club reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-10-21. 501 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2020-10-21
Sam's Club notified Montana residents of a data breach in October 2020. Unauthorized parties used stolen login credentials (likely from a third-party source) to access member accounts in mid-September 2020. Affected data included names, contact info, membership IDs, and Cash Rewards balances. Sam's Club reset passwords, issued new membership numbers, held Cash Rewards, and offered one year of free credit monitoring via Experian.
- Oregon State AGas victim2020-10-21
Sam's West, Inc. dba Sam's Club reported a data breach to the Oregon Attorney General. The breach was reported on 2020-10-21. The breach occurred during 9/17/2020 - 9/24/2020. The breach was discovered on 9/24/2020. 285,885 individuals were affected. Notice was sent on 10/21/2020.
- Washington State AGas victim2020-10-21
Sam's Club notified Washington AG of a cyberattack where unauthorized parties used stolen credentials to access member accounts and conduct fraudulent transactions involving Cash Rewards. Approximately 771 Washington residents were affected. Data accessed included names, contact info, and financial account details. Sam's Club reset passwords, issued new membership numbers, and offered credit monitoring.
- Delaware State AGas victim2020-10-21
Sam's Club notified affected individuals in Delaware and other states that an unauthorized party used stolen login credentials (likely from a third-party source) to access accounts in mid-September 2020. The incident involved access to names, addresses, and Cash Rewards balances. Sam's Club reset passwords, issued new membership numbers, and offered one year of free credit monitoring via Experian.