Walgreens reported a data breach to the Montana Attorney General. The breach was reported on 2024-10-01. The breach occurred from 7/22/2024 to 8/17/2024. 3 Montana residents were affected.
Affected (this filing): 3
Clustered 3 filings across 3 jurisdictions · filing window Oct 1, 2024 → Jul 14, 2025. View entity profile → Other incidents for this victim →
incident inc_00daa43f75604f0a · merge_method deterministic · confidence 100%
Gap between first leak claim and first regulatory filing
Time between earliest and latest filing
Not recorded for this incident
Discovery variance · Materiality delta · SEC filing delay — needs two dated filings.
FEDERAL MT
Leak Site · SEC 10-K Item 1C · State AG
Earliest sighting first · deep chronology in Litigation Timeline
Jul 22, 2024
When the intrusion reportedly occurred, per the linked filings
Walgreens reported a data breach to the Montana Attorney General. The breach was reported on 2024-10-01. The breach occurred from 7/22/2024 to 8/17/2024. 3 Montana residents were affected.
Affected (this filing): 3
Walgreens Boots Alliance (WBA) filed its 2024 Form 10-K disclosing its cybersecurity risk management strategy under Item 1C. The filing describes a comprehensive governance structure involving the CIO, CISO, TRC, and Audit Committee. It details the Data Security Event Plan (DSEP) and engagement of third-party experts for forensics and legal counsel. As of the filing date, WBA stated it was not aware of any cybersecurity threats that have materially affected its business or results of operations.
Walgreens is an American pharmaceutical retail company, established in 1901. It is one of the largest US drugstore chains, known for selling prescription and non-prescription drugs, health and wellness products, cosmetics, and groceries. It also offers health services like immunization and patient care clinics. Often, Walgreens operates 24/7 to allow customers access to their products and services at any hour.
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.