Lowe's Companies, Inc. notified California AG that a third-party vendor's unsecured backup server containing personal information of current and former drivers and employees was accessible from the internet. Data exposure occurred between July 2013 and April 2014. Affected data included names, addresses, DOBs, SSNs, and driver's license numbers. Lowe's blocked access, engaged forensic experts, and provided one year of credit monitoring.