Rite Aid says vendor software flaw exposed data on 24,400 customers

Organization
Rite Aid
Exploit
Supply Chain Attack
Industry
Retail Pharmacy

Rite Aid disclosed in July 2023 that a vulnerability in software supplied by one of its vendors had been exploited, exposing personal information belonging to approximately 24,400 customers.

The pharmacy chain said the vendor alerted it to the flaw on May 31, 2023 and that it applied the vendor's patch immediately. A forensic investigation determined the data had already been taken. Rite Aid's notice of data breach says the files were accessed on May 27, 2023, four days before the vendor reported the flaw.

The affected information included customers' first and last names, dates of birth, addresses, prescription details such as medication names and fill dates, prescriber information and, in some cases, limited insurance data including plan names and cardholder identification numbers. Rite Aid said Social Security numbers and financial information were not exposed.

The company said it reported the incident to law enforcement and to federal and state regulators, carried out a wider review of its systems and told affected customers they were entitled to a free annual credit report from the national consumer reporting agencies.

Rite Aid did not name the vendor or the product. HIPAA Journal linked the incident to Clop's exploitation of the MOVEit Transfer zero day, an attribution the company itself did not make.

Sources