Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Rite Aid did suffer a real data breach, but it happened in June 2024—not in 2026. RansomHub claimed responsibility and described a ransomware-related extortion operation, while Rite Aid confirmed a cybersecurity incident without publicly verifying that the group was the attacker. Maine breach records listed approximately 2.2 million affected people. The reported data included names, addresses, birth dates, driver’s-license or other government-ID numbers, and Rite Aid Rewards numbers tied to older transactions.
Rite Aid said Social Security numbers, financial information and patient information were not affected. No separate, newly confirmed 2026 Rite Aid ransomware breach is established by the available records.
What happened and when?
State breach notifications say an unknown person obtained access to Rite Aid systems on June 6, 2024, after allegedly impersonating a company employee. Rite Aid discovered the incident on June 20 and began notifying consumers on July 15.
Rite Aid described the event as a limited cybersecurity incident and said it restored affected systems with help from an outside cybersecurity partner. The Maine Attorney General filing listed approximately 2.2 million affected individuals, including 30,137 Maine residents. The national figure comes from the company’s breach notification, not an independent audit. See the Maine breach notice and California filing.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
What did RansomHub claim?
RansomHub listed Rite Aid on its leak site, demanded payment and threatened to release stolen information. The group claimed it had taken more than 10 GB of data—described as roughly 45 million “lines” of personal information—and posted a screenshot as alleged proof. It said the material included names, addresses, dates of birth, driver’s-license identifiers and Rite Aid Rewards numbers.
Those statements remain threat-actor claims. Rite Aid confirmed a breach but did not independently confirm that RansomHub conducted the intrusion. The available reporting does not establish that all 10 GB or 45 million lines were genuine, that the full data set was published, that files were encrypted, or that Rite Aid paid or refused a ransom. BleepingComputer’s contemporaneous report records the distinction.
What information was involved?
| Reportedly involved | Rite Aid said was not involved |
|---|---|
| Names | Social Security numbers |
| Addresses | Financial information |
| Dates of birth | Patient information |
| Driver’s-license or other government-issued ID numbers | |
| Rite Aid Rewards numbers |
The records reportedly related to purchases or attempted purchases made between June 6, 2017, and July 30, 2018. That makes this a breach of historical retail and loyalty information, not necessarily current pharmacy or prescription records. Retail Dive describes the transaction period in its coverage.
A driver’s-license number is not a Social Security number. Even without payment-card or Social Security data, a combination of name, address, birth date and government-ID information can make phishing, impersonation and identity-theft attempts more convincing.
Recommended Free Tools
Does “breached again” mean there was a new 2026 attack?
No separate 2026 Rite Aid ransomware breach has been verified in the available records. “Again” refers to an earlier Rite Aid-related breach disclosed in 2023. The 2023 and 2024 events should be treated as separate incidents: no reviewed source establishes that they involved the same attacker, vulnerability, systems or data.
The company structure also changed. Rite Aid LLC, the successor business, acquired selected assets—including the legacy Rewards program—through bankruptcy on January 15, 2026. Its privacy policy, effective March 5, 2026, says the acquired loyalty data did not include prescription records, pharmacy data or protected health information. That policy concerns the successor company and does not independently confirm or disprove the 2024 incident. See Rite Aid’s current privacy policy.
What should affected consumers do now?
The notification period has passed, so start with the notice you received rather than assuming a new claim or enrollment window exists.
- Find and verify the breach letter. Check whether it specifically identified you and whether it supplied a Kroll enrollment code or deadline. Use contact details printed in the letter or verified through official channels—not links in unexpected messages.
- Freeze your credit with all three bureaus. A freeze is free and blocks most new creditors from accessing your file until you lift it. Use the official Equifax, Experian and TransUnion pages.
- Consider a fraud alert. A one-year alert is less restrictive than a freeze and asks creditors to take extra steps to verify your identity.
- Review reports and accounts. Obtain reports through AnnualCreditReport.com. Look for unfamiliar inquiries, new addresses, collection accounts, utility accounts or other activity connected to your identity.
- Expect targeted phishing. Do not send a driver’s-license image, account credentials or one-time code to an unsolicited caller, email or text claiming to be Rite Aid or Kroll.
- Use the offered assistance if it is still available. Rite Aid’s notice offered 12 months of Kroll credit monitoring, fraud consultation and identity-theft restoration. That benefit is for people identified in the notice; it is not evidence that everyone needs to buy Kroll separately. Kroll’s service information is at kroll.com.
- Report suspected identity theft. Use IdentityTheft.gov and contact affected creditors directly. Preserve the breach letter, suspicious messages, statements, credit reports and records of related expenses.
What about the lawsuits and settlement?
A consolidated complaint filed in September 2024 alleged delays or omissions in Rite Aid’s breach notices. Those are plaintiffs’ allegations, not adjudicated findings. A federal court document dated July 30, 2025 reported a proposed $6.8 million settlement in related litigation. The existence of a proposed settlement does not by itself establish liability or guarantee that a claim window remains open. Review the official court or settlement administrator information before relying on any deadline. The complaint is available at riteaiddatasettlement.com, and the court document at govinfo.gov.
Best Value
Key dates
| Date | Event |
|---|---|
| June 6, 2024 | Intrusion date listed in state notifications. |
| June 20, 2024 | Rite Aid discovered the incident. |
| July 12, 2024 | Reporting described Rite Aid’s confirmation after RansomHub’s claim. |
| July 15, 2024 | Consumer notifications began; the Maine filing listed about 2.2 million people nationally. |
| September 16, 2024 | Consolidated complaint filed in related litigation. |
| July 30, 2025 | Federal court document reported a proposed $6.8 million settlement. |
| January 15, 2026 | Rite Aid LLC acquired selected assets, including the legacy Rewards program. |
| March 5, 2026 | Current Rite Aid privacy policy took effect. |
The Bottom Line
The confirmed event was a June 2024 Rite Aid breach affecting approximately 2.2 million people. RansomHub claimed it was responsible, but that attribution was never independently confirmed. The reported exposure involved historical identity and Rewards data—not Social Security, financial or patient information according to Rite Aid. Treat any follow-up message as potentially targeted phishing, freeze your credit if appropriate, and rely on your original breach notice for assistance details.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




