Sam's Club
ent_28e40b0c96bb435e27733263
Disclosures
9
State AG · 7 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
285,885
as filed · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Sam's Club
- Normalized
- sam s club— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- samsclub.com
Disclosure history (9)newest first
- ⛰️New Hampshire State AGas victim2020-12-22
Sam's Club notified the New Hampshire Attorney General on December 18, 2020, of a data security incident discovered on November 19, 2020. An unauthorized party used stolen credentials (email and password) from an unrelated source to access member accounts. The attacker may have conducted fraudulent transactions involving Sam's Club Cash Rewards and accessed personal information including names, addresses, membership IDs, and partial payment card details. One New Hampshire resident was affected. Sam's Club reset passwords, implemented fraud defenses, and offered one year of credit monitoring.
- 🦞Maine State AGas victim2020-12-10
Sam's Club experienced an account takeover incident via credential stuffing, where an unauthorized third party gained access to customer accounts. The breach resulted in the exposure of financial account numbers or credit/debit card numbers, along with their security codes or PINs. Affected individuals were offered 12 months of identity theft monitoring and restoration services through Experian.
- 🦬Montana State AGas victim2020-12-10
Sam's Club reported a data breach to the Montana Attorney General. The breach was reported on 2020-12-10. The breach occurred on 11/10/2020. 1 Montana residents were affected.
- 🦞Maine State AGas victim2020-10-22
Sam's Club reported a data breach occurring between September 17 and 24, 2020, discovered on September 24, 2020. The incident involved account takeover via credential stuffing, affecting 285,885 individuals, including 1,038 in Maine. Compromised data included names and financial account numbers (credit/debit card numbers with security codes/PINs). Sam's Club notified consumers in writing on October 21, 2020, and offered 12 months of credit monitoring and ID restoration services through Experian.
- 🐻California State AGas victim2020-10-21
Sam's Club reported a data security breach to the California Attorney General. The incident occurred on September 24, 2020. The provided source document contains only the filing metadata and an empty attachment placeholder; no narrative details regarding the nature of the breach, data types affected, or response actions are available in the text.
- 🦬Montana State AGas victim2020-10-21
Sam's Club reported a data breach to the Montana Attorney General. The breach was reported on 2020-10-21. The breach occurred from 9/13/2020 to 9/24/2020. 704 Montana residents were affected.
- 🦫Oregon State AGas victim2020-10-21
Sam's West, Inc. dba Sam's Club reported a data breach to the Oregon Attorney General. The breach was reported on 2020-10-21. The breach occurred during 9/17/2020 - 9/24/2020. The breach was discovered on 9/24/2020. 285,885 individuals were affected. Notice was sent on 10/21/2020.
- 🌲Washington State AGas victim2020-10-21
Sam's Club, a business sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2020-09-24 and filed notice on 2020-10-21. 771 Washington residents were affected. 27 days elapsed between awareness and notification. 0 days to contain the breach.
- 💎Delaware State AGas victim2020-10-21
This document is a blank notification letter template filed with the Delaware Attorney General's office by Sam's Club in October 2020. The PDF contains no incident details, dates, or affected individual counts.