Confirmed breach. Intrusion Dec 24, 2020–Dec 29, 2020, discovered Jan 23, 2021 — the first regulatory filing landed 27 days later. 1,474,284 individuals reported across the linked filings.
The Kroger Co. reported to HHS on 2021-02-19 a Hacking/IT Incident affecting 1,474,284 individuals. The breach involved a business associate's cyberattack on a network server, exposing PHI including names, SSNs, DOBs, and treatment data. The entity provided credit monitoring and discontinued the compromised file transfer appliance.
Affected (this filing): 1,474,284
Most recent
4 State AG filingsFeb 19, 2021 – Mar 17, 2021ExpandCollapse
CAWASCMT
California State AG
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
The Kroger Co. reported a data security incident involving its third-party file transfer vendor, Accellion. An unauthorized actor exploited a vulnerability in Accellion's service to access files containing employee and patient information, including names, SSNs, and health data. The incident was discovered on January 23, 2021. Kroger discontinued the service, notified law enforcement, and provided two years of credit monitoring to affected individuals.
🌲Washington State AGlinked via same-victim cross-source · 100%
The Kroger Co., a business sector entity reported a malware incident to the Washington Attorney General. The organization became aware of the incident on 2021-01-23 and filed notice on 2021-02-19. 153,800 Washington residents were affected. 27 days elapsed between awareness and notification. 30 days to identify the breach. 0 days to contain the breach.
Affected (this filing): 153,800
WA AG ≤30d
🌴South Carolina State AGlinked via same-victim cross-source · 100%
The Kroger Co. notified South Carolina residents of a data breach involving Accellion, a third-party secure file transfer service. An unauthorized party exploited a vulnerability in Accellion's service to access files containing associate benefit information, including names, contact info, DOB, and health plan details. Kroger discontinued the service, reported to law enforcement, and offered 2 years of credit monitoring.
🦬Montana State AGlinked via operator-confirmed · 100%
Kroger Company reported a data breach to the Montana Attorney General. The breach was reported on 2021-03-17. The breach occurred from 12/24/2020 to 12/29/2020. 8 Montana residents were affected.