Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Incident Response

Kroger Notifies Customers of Data Breach Stemming from Third-Party Email Vendor

Epsilon Data Breach Update: Other Epsilon customers affected by the breach include JPMorgan Chase, Capital One, Marriott Rewards,  McKinsey’s online publication, McKinsey Quartery, specialty apparel chain New York & Company, Inc. and TiVo.

Epsilon Data Breach Update: Other Epsilon customers affected by the breach include JPMorgan Chase, Capital One, Marriott Rewards,  McKinsey’s online publication, McKinsey Quartery, specialty apparel chain New York & Company, Inc. and TiVo.

Updated Story Published: Massive Breach at Epsilon Compromises Customer Lists of Major Brands

Grocery giant, The Kroger Co., notified customers today that the database storing its customers’ names and email addresses had been breached. The company said incident occurred at Epsilon, the third-party vendor Kroger uses to manage its customer email database and communications.

Kroger stressed to its customers that the only information obtained was names and email addresses of customers.

Related Resource: How to Protect Your Organization Against Advanced Persistent Threats

In a separate announcement, Epsilon said that on March 30th, an incident was detected where a subset of its clients’ customer data were exposed by an unauthorized entry into Epsilon’s email system. Epsilon says a rigorous assessment determined that no other personal identifiable information associated with those names was at risk and that a full investigation is currently underway.

An Epsilon spokesperson told SecurityWeek that it was unable to provide additional information and identify which clients were or weren’t impacted by the incident.

Kroger urged customers not to open email from senders they do not know and reminded customers that Kroger will never ask for personal information such as credit card numbers or social security numbers in an email.

Advertisement. Scroll to continue reading.

This breach follows several other similar breaches from email service providers including The American Honda Motor Co., McDonald’s, and Walgreens.

Kroger is the nation’s largest traditional grocery retailer and employs more than 338,000 associates with stores in 31 states under two dozen local banner names including Kroger, City Market, Dillons, Jay C, Food 4 Less, Fred Meyer, Fry’s, King Soopers, QFC, Ralphs and Smith’s.

How to Protect Your Organization Against Advanced Persistent Threats

Read More Cybercrime Columns in the SecurityWeek Cybercrime Section

Written By

For more than 10 years, Mike Lennon has been closely monitoring the threat landscape and analyzing trends in the National Security and enterprise cybersecurity space. In his role at SecurityWeek, he oversees the editorial direction of the publication and is the Director of several leading security industry conferences around the world.

Click to comment

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

SecurityWeek’s Threat Detection and Incident Response Summit brings together security practitioners from around the world to share war stories on breaches, APT attacks and threat intelligence.

Register

Securityweek’s CISO Forum will address issues and challenges that are top of mind for today’s security leaders and what the future looks like as chief defenders of the enterprise.

Register

Expert Insights

Related Content

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Data Breaches

LastPass DevOp engineer's home computer hacked and implanted with keylogging malware as part of a sustained cyberattack that exfiltrated corporate data from the cloud...

Application Security

GitHub this week announced the revocation of three certificates used for the GitHub Desktop and Atom applications.

Data Breaches

GoTo said an unidentified threat actor stole encrypted backups and an encryption key for a portion of that data during a 2022 breach.

Incident Response

Microsoft has rolled out a preview version of Security Copilot, a ChatGPT-powered tool to help organizations automate cybersecurity tasks.

Incident Response

Meta has developed a ten-phase cyber kill chain model that it believes will be more inclusive and more effective than the existing range of...

Artificial Intelligence

Two new surveys stress the need for automation and AI – but one survey raises the additional specter of the growing use of bring...

Application Security

Password management firm LastPass says the hackers behind an August data breach stole a massive stash of customer data, including password vault data that...