Rite Aid confirms data breach following ransomware attack

Code Skull
(Image credit: Shutterstock)

American drugstore chain Rite Aid has confirmed that last month’s ransomware attack resulted in data theft.

In a statement, the company said it was currently investigating the cyberattack, and is working on sending out data breach notifications to affected customers.

"Rite Aid experienced a limited cybersecurity incident in June, and we are finalizing our investigation. We take our obligation to safeguard personal information very seriously, and this incident has been a top priority," Rite Aid said. "Together with our third-party cybersecurity partner experts, we have restored our systems and are fully operational. We are sending notices to impacted consumers."

RansomHub

The company did not say how many people are affected by the incident, nor did it detail the type of data that was stolen.

However Rite Aid did say what information was not stolen - health information, and financial data, noting, "we can confirm that no social security numbers, financial information, or patient information were impacted by this incident."

At the same time, a ransomware operation called RansomHub assumed responsibility for the attack, and shared more details on its data leak page:

"While having access to the Riteaid network we obtained over 10 GB of customer information equating to around 45 million lines of people's personal information. This information includes name, address, dl_id number, dob, riteaid rewards number," the group apparently wrote on its dark web page.

It added that Rite Aid did not follow through with a ransom negotiation, which is why it plans to leak everything in roughly two weeks. 

RansomHub is a relatively new threat actor, spun out of the defunct ALPHV (AKA BlackCat). In early 2024, an affiliate of ALPHV broke into Change Healthcare, stole a huge database of sensitive information, and demanded $22 million in ransom. Since ALPHV operates on a Ransomware-as-a-Service (RaaS) model, the payment was made to ALPHV operators, which should have then shared the spoils with the affiliate that made the breach.

Instead, the operators took all of the money and disappeared, leaving the affiliate with no money and a lot of sensitive Change Healthcare data. This affiliate was later rebranded to RansomHub, and even demanded more money from Change Healthcare at one point. 

Via BleepingComputer

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
security
Ransomware gangs allegedly hit two major US healthcare firms, 300,000 patients have data stolen
ransomware avast
The biggest addiction treatment provider in the US says it was hit by data breach
ID theft
Over a million patients potentially hit after another US healthcare provider hit by cyberattack
Lock on Laptop Screen
United Healthcare data breach may have affected 190 million Americans
Ransomware
Top cannabis brand Stiiizy says hackers got access to its systems
Data leak
Ransomware attackers leak stolen Rhode Island private info following hack
Latest in Security
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Latest in News
Zotac Gaming RTX 5090 Graphics Card
Nvidia Blackwell stock woes are compounded by price hikes as more RTX 5090 GPUs soar in pricing, and I’m sick and tired of it all at this point
A collage of Elizabeth Olsen's Scarlet Witch and Tatiana Maslany's She-Hulk
Marvel fans are already tired of Doomsday and Secret Wars cast gossip as two more superheroes get linked with roles in the next two Avengers movies
Four operators survey Verdansk. One holds a sniper rifle, one binoculars, another holds is landing with their parachute, while the last wears a skull mask
New Call of Duty: Warzone trailer shows a beautiful rebuilt Verdansk, but some fans want more: 'it won't be the same unfortunately'
An Apple Music pink/pixellated poster advertising DJ with Apple Music
DJ with Apple Music lands, allowing subscribers to build and mix DJ sets directly from its +100 million-song catalog
The Meta Quest 3 and controllers on their charging station which is itself on a wooden desk next to a lamp
Forget Android XR, I've got my eyes on Vivo's new Meta Quest 3 competitor as it could be the most important VR headset of 2025
Samsung Galaxy S25 from the front
The Now Bar on Samsung One UI 7 is about to get a lot more useful – and could soon match Live Activities on iOS