Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Incident Response

Kroger Notifies Customers of Data Breach Stemming from Third-Party Email Vendor

Epsilon Data Breach Update: Other Epsilon customers affected by the breach include JPMorgan Chase, Capital One, Marriott Rewards,  McKinsey’s online publication, McKinsey Quartery, specialty apparel chain New York & Company, Inc. and TiVo.

Epsilon Data Breach Update: Other Epsilon customers affected by the breach include JPMorgan Chase, Capital One, Marriott Rewards,  McKinsey’s online publication, McKinsey Quartery, specialty apparel chain New York & Company, Inc. and TiVo.

Updated Story Published: Massive Breach at Epsilon Compromises Customer Lists of Major Brands

Grocery giant, The Kroger Co., notified customers today that the database storing its customers’ names and email addresses had been breached. The company said incident occurred at Epsilon, the third-party vendor Kroger uses to manage its customer email database and communications.

Kroger stressed to its customers that the only information obtained was names and email addresses of customers.

Related Resource: How to Protect Your Organization Against Advanced Persistent Threats

In a separate announcement, Epsilon said that on March 30th, an incident was detected where a subset of its clients’ customer data were exposed by an unauthorized entry into Epsilon’s email system. Epsilon says a rigorous assessment determined that no other personal identifiable information associated with those names was at risk and that a full investigation is currently underway.

An Epsilon spokesperson told SecurityWeek that it was unable to provide additional information and identify which clients were or weren’t impacted by the incident.

Kroger urged customers not to open email from senders they do not know and reminded customers that Kroger will never ask for personal information such as credit card numbers or social security numbers in an email.

This breach follows several other similar breaches from email service providers including The American Honda Motor Co., McDonald’s, and Walgreens.

Advertisement. Scroll to continue reading.

Kroger is the nation’s largest traditional grocery retailer and employs more than 338,000 associates with stores in 31 states under two dozen local banner names including Kroger, City Market, Dillons, Jay C, Food 4 Less, Fred Meyer, Fry’s, King Soopers, QFC, Ralphs and Smith’s.

How to Protect Your Organization Against Advanced Persistent Threats

Read More Cybercrime Columns in the SecurityWeek Cybercrime Section

Written By

For more than 15 years, Mike Lennon has been closely monitoring the threat landscape and analyzing trends in the National Security and enterprise cybersecurity space. In his role at SecurityWeek, he oversees the editorial direction of the publication and is the Director of several leading security industry conferences around the world.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Understand how to go beyond effectively communicating new security strategies and recommendations.

Register

Join us for an in depth exploration of the critical nature of software and vendor supply chain security issues with a focus on understanding how attacks against identity infrastructure come with major cascading effects.

Register

Expert Insights

Related Content

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Data Breaches

LastPass DevOp engineer's home computer hacked and implanted with keylogging malware as part of a sustained cyberattack that exfiltrated corporate data from the cloud...

Incident Response

Microsoft has rolled out a preview version of Security Copilot, a ChatGPT-powered tool to help organizations automate cybersecurity tasks.

Data Breaches

GoTo said an unidentified threat actor stole encrypted backups and an encryption key for a portion of that data during a 2022 breach.

Application Security

GitHub this week announced the revocation of three certificates used for the GitHub Desktop and Atom applications.

Incident Response

Meta has developed a ten-phase cyber kill chain model that it believes will be more inclusive and more effective than the existing range of...

Cloud Security

VMware described the bug as an out-of-bounds write issue in its implementation of the DCE/RPC protocol. CVSS severity score of 9.8/10.