Security Experts:

Kroger Notifies Customers of Data Breach Stemming from Third-Party Email Vendor

Epsilon Data Breach Update: Other Epsilon customers affected by the breach include JPMorgan Chase, Capital One, Marriott Rewards,  McKinsey's online publication, McKinsey Quartery, specialty apparel chain New York & Company, Inc. and TiVo.

Updated Story Published: Massive Breach at Epsilon Compromises Customer Lists of Major Brands

Grocery giant, The Kroger Co., notified customers today that the database storing its customers' names and email addresses had been breached. The company said incident occurred at Epsilon, the third-party vendor Kroger uses to manage its customer email database and communications.

Kroger stressed to its customers that the only information obtained was names and email addresses of customers.

Related Resource: How to Protect Your Organization Against Advanced Persistent Threats

In a separate announcement, Epsilon said that on March 30th, an incident was detected where a subset of its clients' customer data were exposed by an unauthorized entry into Epsilon's email system. Epsilon says a rigorous assessment determined that no other personal identifiable information associated with those names was at risk and that a full investigation is currently underway.

An Epsilon spokesperson told SecurityWeek that it was unable to provide additional information and identify which clients were or weren’t impacted by the incident.

Kroger urged customers not to open email from senders they do not know and reminded customers that Kroger will never ask for personal information such as credit card numbers or social security numbers in an email.

This breach follows several other similar breaches from email service providers including The American Honda Motor Co., McDonald’s, and Walgreens.

Kroger is the nation's largest traditional grocery retailer and employs more than 338,000 associates with stores in 31 states under two dozen local banner names including Kroger, City Market, Dillons, Jay C, Food 4 Less, Fred Meyer, Fry's, King Soopers, QFC, Ralphs and Smith's.

How to Protect Your Organization Against Advanced Persistent Threats

Read More Cybercrime Columns in the SecurityWeek Cybercrime Section