Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Incident Response

Kroger Notifies Customers of Data Breach Stemming from Third-Party Email Vendor

Epsilon Data Breach Update: Other Epsilon customers affected by the breach include JPMorgan Chase, Capital One, Marriott Rewards,  McKinsey’s online publication, McKinsey Quartery, specialty apparel chain New York & Company, Inc. and TiVo.

Epsilon Data Breach Update: Other Epsilon customers affected by the breach include JPMorgan Chase, Capital One, Marriott Rewards,  McKinsey’s online publication, McKinsey Quartery, specialty apparel chain New York & Company, Inc. and TiVo.

Updated Story Published: Massive Breach at Epsilon Compromises Customer Lists of Major Brands

Grocery giant, The Kroger Co., notified customers today that the database storing its customers’ names and email addresses had been breached. The company said incident occurred at Epsilon, the third-party vendor Kroger uses to manage its customer email database and communications.

Kroger stressed to its customers that the only information obtained was names and email addresses of customers.

Related Resource: How to Protect Your Organization Against Advanced Persistent Threats

In a separate announcement, Epsilon said that on March 30th, an incident was detected where a subset of its clients’ customer data were exposed by an unauthorized entry into Epsilon’s email system. Epsilon says a rigorous assessment determined that no other personal identifiable information associated with those names was at risk and that a full investigation is currently underway.

An Epsilon spokesperson told SecurityWeek that it was unable to provide additional information and identify which clients were or weren’t impacted by the incident.

Advertisement. Scroll to continue reading.

Kroger urged customers not to open email from senders they do not know and reminded customers that Kroger will never ask for personal information such as credit card numbers or social security numbers in an email.

This breach follows several other similar breaches from email service providers including The American Honda Motor Co., McDonald’s, and Walgreens.

Kroger is the nation’s largest traditional grocery retailer and employs more than 338,000 associates with stores in 31 states under two dozen local banner names including Kroger, City Market, Dillons, Jay C, Food 4 Less, Fred Meyer, Fry’s, King Soopers, QFC, Ralphs and Smith’s.

How to Protect Your Organization Against Advanced Persistent Threats

Read More Cybercrime Columns in the SecurityWeek Cybercrime Section

Written By

For more than 15 years, Mike Lennon has been closely monitoring the threat landscape and analyzing trends in the National Security and enterprise cybersecurity space. In his role at SecurityWeek, he oversees the editorial direction of the publication and is founder and director of several leading cybersecurity industry conferences around the world.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Erika Dean has been appointed Chief Information Security Officer at Tricentis.

C1 has named Jeff St. Clair Chief Revenue Officer.

John Opala has joined Ralph Lauren as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.