Data breach
Rite Aid
- Records
- 12,316,882
- Breach date
- 6 June 2024Estimated
- Added
- 24 January 2025
What was exposed
4 types of data · 2 more reported · 1 puts you at serious risk
- Phone numbers12,316,882
- Driving licence numbers10,828,988
- Names10,579,079
- Home addresses10,574,960
- Government IDsReported, not counted
- Dates of birthReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In June 2024, pharmacy chain Rite Aid suffered a data breach after a third party impersonated a company employee, compromised business credentials, and gained access to company systems. According to a breach notification Rite Aid filed with the Office of the Maine Attorney General, the intrusion took place on June 6, 2024, and was detected within 12 hours. By that point, the attackers had already taken customer data. The ransomware group RansomHub claimed responsibility, saying it stole tens of gigabytes of information, and reported that negotiations with the company broke down.
The investigation team indexes this listing at a larger scale: 12,316,882 records, including 12,316,882 phone numbers, 10,828,988 driver's license entries, 10,579,079 names, and 10,574,960 home addresses. The team estimates the attack date as June 6, 2024. Rite Aid's own notice put the number of affected individuals at about 2.2 million, tied to purchases made between June 6, 2017, and July 30, 2018. As of September 25, 2026, no public source reconciles the difference between the company's figure and the larger indexed dataset.
Breach Timeline
June 6, 2024: An unauthorized third party accessed Rite Aid systems using credentials compromised through employee impersonation. Rite Aid says it shut down the login within 12 hours.
June 17, 2024: Rite Aid determined that data associated with the purchase or attempted purchase of specific retail products had been acquired by the attacker.
July 15, 2024: Rite Aid began mailing breach notification letters and filed a disclosure with the Maine Attorney General.
What Information Was Compromised?
Our analysis found the following data types in this breach: phone numbers, driver's license entries, names, and home addresses.
Rite Aid's breach notification adds further detail. It says the stolen data included purchaser names, addresses, dates of birth, and driver's license numbers or other forms of government-issued ID presented at the time of a purchase between June 6, 2017, and July 30, 2018. The company stated that no Social Security numbers, financial information, or patient information was affected. RansomHub's own claim also mentioned Rite Aid rewards numbers.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Driver's license numbers combined with names, addresses, and phone numbers give criminals material for identity fraud. Unlike a leaked password, a license number is difficult to change. Scammers can use this data in phishing calls, text messages, and emails that appear legitimate because they reference real personal details. Criminals may also attempt to open accounts or pass identity checks using stolen ID numbers. Because the data includes home addresses, affected people should be alert to targeted scams that reference where they live.
What Is Rite Aid Doing in Response?
Rite Aid said it reported the incident to law enforcement and to federal and state regulators, and that it was implementing additional security measures. The company offered affected customers 12 months of free credit monitoring through Kroll. Several lawsuits were consolidated into a single class action, Bianucci v. Rite Aid Corporation, in the U.S. District Court for the Eastern District of Pennsylvania. Rite Aid later agreed to a $6.8 million settlement, which received preliminary approval in March 2025, without admitting wrongdoing. Rite Aid also committed to improvements to its cybersecurity program as part of that agreement.
What Should You Do If You Were Affected?
If you bought or attempted to buy specific retail products at Rite Aid between June 6, 2017, and July 30, 2018, you may have received a notification letter. Even if you did not, consider these steps:
Check your mail and email for a Rite Aid breach notice and enroll in the credit monitoring offer if you received one.
Monitor your credit reports at annualcreditreport.com and watch for accounts you did not open.
Contact your state motor vehicle agency if you suspect your driver's license number is being misused.
Be skeptical of calls, texts, or emails that cite your name, address, or purchase history. Verify identities independently before responding.
Report identity theft to the FTC at identitytheft.gov if it occurs.
In the news
- The Register: Rite Aid says 2.2 million people's data stolen by attackerstheregister.com (opens in a new tab)
- HIPAA Journal: Rite Aid Settles Data Breach Lawsuit for $6.8 Millionhipaajournal.com (opens in a new tab)
- NBC Boston: Rite Aid says data breach exposed sensitive customer informationnbcboston.com (opens in a new tab)
- CNBC Select: How to claim up to $10,000 from Rite Aid's data breach settlementcnbc.com (opens in a new tab)
