Rite Aid says June cyberattack exposed data on 2.2 million people
- Organization
- Rite Aid
- Exploit
- Ransomware
- Industry
- Retail Pharmacy
Rite Aid disclosed in mid-July 2024 that an unauthorized party had reached its systems the previous month and taken personal data belonging to about 2.2 million people. The drugstore chain characterized the event as a limited cybersecurity incident.
According to the company's account, the intruder impersonated a Rite Aid employee on 6 June 2024 in order to obtain business credentials, then used them to access internal systems. Rite Aid said it identified the activity within 12 hours and cut off the access.
The affected records related to purchases of certain retail products made between 6 June 2017 and 30 July 2018. Rite Aid's notification listed purchaser names, addresses, dates of birth, and driver's license or other government-issued identification numbers.
The RansomHub ransomware operation claimed responsibility and said it had taken more than 10 gigabytes of customer information, which it described as around 45 million lines of data including Rite Aid rewards account numbers. The group set a late-July deadline to publish the files if it was not paid. The Record reported that deadline as 24 July, while Malwarebytes reported it as 26 July.
Rite Aid said it restored the affected systems, contacted law enforcement, and offered affected individuals 12 months of credit monitoring through Kroll, with notices sent by direct mail. The company did not say whether it intended to pay.