Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Dollar Tree Impacted by ZeroedIn Data Breach Affecting 2 Million Individuals

ZeroedIn says personal information of 2 million individuals was compromised in an August 2023 data breach that impacts customers such as Dollar Tree.

Workforce analytics services provider ZeroedIn is notifying roughly two million individuals that their personal information was compromised in an August 2023 data breach.

In a filing with the Maine Attorney General’s Office, the company revealed that the incident was identified on August 8, and that a threat actor had unauthorized access to certain systems between August 7 and 8.

The company immediately launched an investigation into the incident, which determined that some of the files accessed or stolen by the attackers contained personal information.

After conducting a review of the files on the compromised systems, ZeroedIn discovered that the accessed data pertained to certain customers, including US variety store chains Dollar Tree and Family Dollar.

ZeroedIn says it notified Dollar Tree of the incident after determining that some of the compromised information pertained to “certain individuals associated with them”.

The attackers, the company says, accessed or stole files containing names, dates of birth, and Social Security numbers.

In the sample notification letter submitted to the Maine Attorney General’s Office, ZeroedIn notes that the compromised information is related to “applicants and current and former employees of its clients”.

The company told the Maine Attorney General’s Office that close to two million individuals were impacted by the incident, with the filing suggesting that only individuals related to Dollar Tree and Family Dollar might have been impacted.

Advertisement. Scroll to continue reading.

Per Dollar Tree’s latest 10-Q filing with the US Securities and Exchange Commission, more than 16,600 retail discount stores and 17 distribution centers in the US and Canada operate under the Dollar Tree and Family Dollar brands.

ZeroedIn may face a class action suit over the incident, as data breach lawyers at Console & Associates, P.C. announced they are investigating the matter on behalf of the impacted individuals.

Related: University of Michigan Says Personal Information Stolen in August Data Breach

Related: TransUnion Denies Breach After Hacker Publishes Allegedly Stolen Data

Related: Up to 11 Million People Hit by MOVEit Hack at Government Services Firm Maximus

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn about active threats targeting common cloud deployments and what security teams can do to mitigate them.

Register

Join us for an in depth exploration of the critical nature of software and vendor supply chain security issues with a focus on understanding how attacks against identity infrastructure come with major cascading effects.

Register

Expert Insights

Related Content

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

Cybercrime

Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.

Data Breaches

LastPass DevOp engineer's home computer hacked and implanted with keylogging malware as part of a sustained cyberattack that exfiltrated corporate data from the cloud...

CISO Strategy

Okta is blaming the recent hack of its support system on an employee who logged into a personal Google account on a company-managed laptop.

Data Breaches

A group of hackers has leaked Atlassian employee records and floorplans, information that was obtained from third-party workplace platform Envoy.

Data Breaches

Sony shares information on the impact of two recent unrelated hacker attacks carried out by known ransomware groups. 

Data Breaches

KFC and Taco Bell parent company Yum Brands says personal information was compromised in a January 2023 ransomware attack.

Data Breaches

Delta Dental of California says over 6.9 million individuals were impacted by a data breach caused by the MOVEit hack.