Rite Aid reported that an unauthorised party accessed its systems on 6 June 2024 and that the intrusion was identified within twelve hours. The company said around 2.2 million people were affected. The RansomHub operation claimed it had taken over 10GB covering approximately 45 million individuals. Rite Aid later settled related litigation for $6.8 million.
Twenty Times Apart
A gap between a company figure and an operation’s claim is normal in this file set. A gap of this size is not: 2.2 million against 45 million is not a rounding difference or a disagreement about scope.
One of the two is wrong, and from outside we cannot say which. Operations routinely inflate; companies count only what they can attribute to identifiable individuals. We print both figures, label the source of each, and grade the file on the company’s number because it is the one with a name behind it.
Twelve Hours Is Genuinely Fast
Detection inside half a day is at the good end of anything recorded here, against dwell times that routinely run to months.
It did not prevent exfiltration. Speed of detection and volume taken turn out to be close to independent — an operation that intends to copy and leave does not need long.
Compiled from the company’s notifications, public reporting and settlement coverage, listed below. The 45 million figure is RansomHub’s claim about its own haul and is not corroborated. Corrections: corrections@forensicpost.com.