Skip navigation
Rite_Aid_updated_store_banner-closeup 1.jpg Getty Images
Letters were mailed to customers on July 20 from Rite Aid, stating that it regrets the incident and that the breach was immediately reported to law enforcement along with federal and state regulators.

Rite Aid reports major data breach

Customer information was compromised in May

Rite Aid said a major data breach that occurred on May 27 has compromised the personal information of customers, reports CBS 21 News.

The drugstore chain based in Philadelphia, Pa., was notified by a vendor partner of a vulnerability in Rite Aid's software that had been exploited by an unknown third party on May 31.

Letters were mailed to customers on July 20 from Rite Aid, stating that it regrets the incident and that the breach was immediately reported to law enforcement along with federal and state regulators.

The vendor provided a software update to correct the vulnerability during a review of Rite Aid's systems and the software, and it was discovered that on May 27 certain company files had been accessed by the unknown third party.

The drug store chain said the data exposed included names, birth dates, addresses, and prescription information. In some cases, insurance information — like plan names and cardholder IDs — was accessed, but social security numbers and credit card information were not compromised, according to local news outlet, WGAL.

Rite Aid recently hired a new chief legal officer in June, but it is unclear if the move was related to the security breach. Thomas Sabatino was brought on to “oversee the organization’s legal affairs, including enterprise risk management, compliance, regulatory affairs, and privacy,” according to the release.

 


 

Hide comments

Comments

  • Allowed HTML tags: <em> <strong> <blockquote> <br> <p>

Plain text

  • No HTML tags allowed.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.
Publish