The giant supermarket chain Kroger suffered a data breach after a service used for secure file transfer was compromised and hackers stole files.
Kroger is one of the largest retailers in the world, with nearly 2,800 stores in 35 states. Kroger employs about 500,000 people and had sales of over $122 billion for 2019.
Yesterday, Kroger revealed that it was the latest company to be affected by a security vulnerability in its Accellion FTA software that allowed hackers to steal data from companies using the service.
According to the data breach advisory published yesterday, the Kroger chain was notified by Accellion of the breach on January 23, 2021 and immediately stopped using the service.
As part of their investigation into the attack, Kroger has concluded that no grocery store data, including payment information. However, the breach did expose human resources data and pharmacy records.
Kroger states that they are in the process of contacting those who were affected. For those who have been impacted, the company offers a free year of credit monitoring.

Accellion attacks have a broad impact
Kroger is just one of the large companies that were affected by the vulnerability in the Accellion FTA service that hackers have exploited in recent months.
In mid-December, Accellion disclosed that it had learned of an active zero-day exploit in its secure file transfer service FTA. Hackers were exploiting the vulnerability to steal data from companies that used the service to securely communicate with their customers and partners.
Accellion released a patch on Christmas Day, but companies received the update and applied it after hackers had already gained access to their data.
Some of those affected by the Accellion breach have received ransom notes from the hackers demanding paymentor their data will be made public.
Information source: bleepingcomputer.com
