October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
Albertsons

2014 Supervalu and Albertsons Point-of-Sale Intrusions: What Happened

SUPERVALU and AB Acquisition disclosed separate 2014 intrusions into payment-card networks. Here are the estimated exposure windows, named banners and regions, and what the companies did—and did not—confirm.

By TheFinanceBase Team 4 min read

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In 2014, two grocery-company disclosures described separate intrusions into payment-card processing networks: SUPERVALU announced one on August 14, followed by a second, distinct incident on September 29. AB Acquisition, which operated Albertsons and other grocery banners, also reported incidents. The companies said card data might have been captured, but their disclosures did not establish that it was stolen or confirm a total number of affected customers or records.

What happened in the first intrusion?

On August 14, 2014, SUPERVALU said criminals had intruded into part of its network that processed payment-card transactions at some retail food stores and associated stand-alone liquor stores. The company estimated that cards used at identified locations from June 22 through July 17, 2014, might have had data collected. Those dates were an estimated exposure window, not proof that every card used then was compromised.

SUPERVALU’s initial August notice named 180 stores and liquor stores. Its October 2014 filing later described the first incident as potentially involving 209 SUPERVALU-owned and franchised stores and liquor stores. These are counts from disclosures made at different times, not a confirmed count of customers or stolen records. The August notice identified Cub Foods, Farm Fresh, Hornbacher’s, Shop ’n Save, and Shoppers Food & Pharmacy; it said Save-A-Lot stores were not included in that initial incident notice.

AB Acquisition’s August account

AB Acquisition reported that stores it operated also experienced a related intrusion. Its August 15 notice listed affected Albertsons regions in Southern California, Idaho, Montana, North Dakota, Nevada, Oregon, Washington, Wyoming, and Southern Utah. It said Albertsons stores in Arizona, Arkansas, Colorado, Florida, Louisiana, New Mexico, and Texas, as well as two Super Saver Foods stores in northern Utah, were not impacted. The same notice listed ACME Markets in Pennsylvania, Maryland, Delaware, and New Jersey; Jewel-Osco in Iowa, Illinois, and Indiana; and Shaw’s and Star Markets in Maine, Massachusetts, Vermont, New Hampshire, and Rhode Island. These are the company’s reported geographic descriptions at that time, not a verified store-by-store count of stolen card data.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How was the second intrusion different?

On September 29, 2014, SUPERVALU announced a second, separate intrusion believed to have taken place in late August or early September. AB Acquisition said the new incident involved different malware from the earlier intrusion. The later event should not be treated as a continuation of one confirmed attack on identical stores or systems.

In its October filing, SUPERVALU said that, at that point in the investigation, the only SUPERVALU-owned or franchised stores where the second incident’s malware may have succeeded in capturing card data were four franchised Cub Foods stores in Minnesota. It estimated possible exposure at some checkout lanes from August 27 through September 21, 2014. AB Acquisition’s September notice separately described banners and regions it believed affected by this second incident and again identified Albertsons regions and the two northern Utah Super Saver Foods stores it considered unaffected. The September descriptions should not be combined with the August counts or read as proof that data theft occurred at every listed location.

What information might have been exposed?

SUPERVALU said potentially collected information could include payment-card account numbers and, in some cases, expiration dates, other numerical information, and/or the cardholder’s name. In its October 2014 filing, the company said it had not determined that data potentially captured by either malware was in fact stolen. AB Acquisition likewise said it had not determined that card data was stolen; its August notice reported no evidence of misuse at that time.

Possible capture is not the same as confirmed theft or misuse. The company notices describe potential exposure periods and affected locations, not a verified number of distinct customers or stolen records. The reviewed company disclosures do not establish a confirmed total for either.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Sale
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
  • Ideal for Gifting
  • Ideal for a bookworm
  • Compact for travelling

What did the companies do?

SUPERVALU said it secured affected portions of its network, believed it had eradicated the malware, notified federal law enforcement and payment-card brands, and cooperated with investigations. The notices described 12 months of complimentary identity-protection services for potentially affected customers at the time. Those were historical offers; the notices do not establish that comparable services remain available today.

In its August 15, 2014 notice, Mark Bates, then Senior Vice President and Chief Information Officer at AB Acquisition LLC, said: “We know our customers are concerned about the security of their payment card data, and we work hard to protect it.”

What did later disclosures say about security and assessments?

Albertsons Companies’ 2018 SEC filing reported that forensic reports found the companies had not met all Payment Card Industry Data Security Standard (PCI DSS) requirements at the time of the intrusions, and that some non-compliance may have contributed to or caused at least part of the compromise. The filing did not identify one specific control failure as the cause.

The same 2018 filing reported that Mastercard asserted an assessment of approximately $6.0 million, which the company said it paid in December 2016 and disputed in a lawsuit. It also reported a $1.0 million Visa assessment paid in fiscal 2017. These were payment-network assessments, not consumer losses or government fines.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The filing’s account of litigation is historical: it said an appellate court had reversed dismissal as to one named plaintiff and affirmed dismissal as to 15 others; a later motion to dismiss the remaining plaintiff was granted with prejudice in March 2018, with an appeal pending at the time of that filing. That does not establish the case’s current status.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Was my credit card affected?

The disclosures identify estimated transaction windows and named stores, banners, or regions, but do not provide a confirmed customer or cardholder list. If you used a payment card at a location identified in a company’s notice during its stated window, the notice indicates possible exposure, not a finding that your card was stolen. The historical notices’ 12-month identity-protection offers are not evidence that enrollment is still available.

For a present concern about a card, contact the issuer using the number on the card or its official website. The issuer can tell you whether the card remains active, whether a replacement is appropriate, and how to report suspicious transactions. Review account activity and report any transaction you do not recognize promptly; do not rely on the 2014 company notices to determine your card’s current status.

Quick Recap

SaleBestseller No. 1
SaleBestseller No. 2
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
Ideal for Gifting; Ideal for a bookworm; Compact for travelling
$10.99
SaleBestseller No. 5
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
It can be a gift option; Comes with secure packaging; Helpful in various ways
$9.15
Best Value
Sale
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
  • It can be a gift option
  • Comes with secure packaging
  • Helpful in various ways

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Money Desk

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.