Cyber Security News

Rite Aid Data Breach – 2.2 Million Customer Personal Data Exposed

Rite Aid, the third-largest drugstore chain in the United States, has disclosed that a data breach in June 2024 exposed the personal information of 2.2 million customers. The company detected unauthorized access to its systems on June 6, 2024, which was carried out by an unknown third party using compromised employee credentials.

The breach affected data associated with purchases or attempted purchases of specific retail products between June 6, 2017, and July 30, 2018. The exposed information includes customers’ names, addresses, dates of birth, and driver’s license numbers or other forms of government-issued ID presented at the time of purchase.

Are you from SOC/DFIR Teams? - Sign up for a free ANY.RUN account! to Analyse Advanced Malware Files

Rite Aid has emphasized that no Social Security numbers, financial information, or patient health information were compromised in the incident. According to letters filed with the Office of Maine’s Attorney General, the company discovered the full extent of the breach by June 17, 2024, and has since been working to address the situation.

In response to the breach, Rite Aid has taken several steps:

  1. Launched an internal investigation to terminate unauthorized access and remediate affected systems.
  2. Reported the incident to law enforcement and federal and state regulators.
  3. Implementing additional security measures to prevent similar attacks in the future.
  4. Sending notification letters to affected customers.
  5. Offering 12 months of complimentary credit and identity theft monitoring services to impacted individuals.

While Rite Aid has not disclosed the identity of the attackers, a ransomware group called RansomHub has claimed responsibility for the breach. The group alleges to have obtained 10GB of customer data, potentially affecting up to 45 million individuals.

However, Rite Aid’s official statement contradicts this claim, reporting a significantly lower number of 2.2 million affected customers.

The incident has raised concerns about cybersecurity in the healthcare sector, with some experts calling for stronger federal regulations to protect patient data and ensure the security of healthcare systems.

Rite Aid has stated that the investigation into the breach is a top priority, and they are working with third-party cybersecurity experts to restore their systems, which are now fully operational. The company continues to emphasize its commitment to safeguarding personal information and addressing the incident promptly.

“Is Your System Under Attack? Try Cynet XDR: Automated Detection & Response for Endpoints, Networks, & Users!”- Free Demo

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

2 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

2 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

3 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

4 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

4 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

5 hours ago