The Rite Aid pharmacy data breach exposed the personal information of 2.2 million customers, resulting in a $6.8 million settlement. If you purchased anything at Rite Aid between June 6, 2017, and July 30, 2018, your name, address, date of birth, and driver’s license information may have been stolen during a ransomware attack that occurred in June 2024. The settlement provides compensation for affected customers, though the deadline to file claims has already passed, leaving those who missed it with limited options for recovery.
The breach itself happened on June 6, 2024, when the RansomHub ransomware group gained access to Rite Aid’s systems. The company didn’t discover or publicly disclose the extent of the data exposure until months later. Rite Aid reached a settlement agreement with affected customers, which received preliminary approval from the court on March 4, 2025, with final approval scheduled for July 17, 2025. However, anyone wanting to pursue this claim faced a strict deadline of July 7, 2025, which has already expired as of July 24, 2026.
Table of Contents
- Who Was Actually Affected by the Rite Aid Data Breach?
- What Information Was Stolen in the Rite Aid Breach?
- The Timeline: When the Breach Happened and How Long It Took to Disclose
- How Much Compensation Could Affected Customers Receive?
- Claim Filing and Common Issues
- What Happens If You Missed the Claim Deadline
- Official Resources and Next Steps
Who Was Actually Affected by the Rite Aid Data Breach?
The breach affected customers who made purchases during a specific 13-month window: June 6, 2017, through July 30, 2018. This wasn’t every Rite Aid customer, just those who shopped during this period. If you bought cold medicine, vitamins, beauty products, or anything else at a Rite Aid location during these dates, your information was potentially exposed.
The timeframe is narrow enough that many customers may not remember whether they shopped at Rite Aid during this specific period. The 2.2 million affected individuals had their names, addresses, dates of birth, and government-issued ID numbers exposed. This wasn’t a limited leak of email addresses or passwords—this was sensitive identity information that criminals actively seek. A customer who purchased a refill at Rite Aid in 2018 would have had all this information compromised, even if they only visited once during that window.
What Information Was Stolen in the Rite Aid Breach?
The data exposed was the kind that identity thieves need to commit fraud. Beyond basic names and addresses, the stolen records included dates of birth and driver’s license numbers or other government-issued ID information. This combination of data is particularly dangerous because it gives criminals the information needed to open credit accounts, file fraudulent tax returns, or commit other forms of identity theft.
The practical danger here is that this type of breach impacts victims for years. A stolen driver’s license number combined with your date of birth and address means a criminal has the building blocks for comprehensive identity fraud. While Rite Aid and the settlement may offer credit monitoring and fraud alert services, these are reactive tools that catch fraud after it happens, not preventative measures. Some victims would already have experienced identity theft claims, fraudulent accounts, or credit damage by the time the settlement was finalized.
The Timeline: When the Breach Happened and How Long It Took to Disclose
The RansomHub ransomware group breached Rite Aid’s systems on June 6, 2024. The company discovered evidence of the breach relatively quickly but took until June 2024 to confirm the scope and begin notifying customers. The delay between the initial breach and public disclosure gave criminals weeks to potentially exploit the exposed data before victims even knew it was compromised.
From June 2024 to March 2025—a nine-month gap—customers waited while lawyers negotiated the settlement terms. The preliminary approval came March 4, 2025, which set the stage for the final court approval hearing in July 2025. Throughout this entire period, victims had to monitor their credit reports and consider placing fraud alerts on their accounts, even though the settlement process was still underway.
How Much Compensation Could Affected Customers Receive?
The settlement fund totaled $6.8 million to be divided among 2.2 million affected customers. The maximum compensation available to any individual victim was up to $10,000 for documented losses. This means if you could prove you suffered identity theft, fraudulent account creation, or credit damage as a direct result of the Rite Aid breach, you could potentially claim up to the full $10,000.
However, the amount paid to each victim depends on how many claims were filed and how much documented loss each person claimed. If 1 million people filed claims, each claim would split fewer of the $6.8 million available. If only 100,000 people filed claims, those individuals would receive larger individual payouts. The final per-victim payment depends entirely on the claim volume, making it impossible to predict how much any single claimant would actually receive.
Claim Filing and Common Issues
The official claim deadline was July 7, 2025, which has now passed. Anyone who missed this deadline cannot file a claim through the standard settlement process. This represents a significant limitation for victims who didn’t learn about the settlement in time or were uncertain whether they actually shopped at Rite Aid during the affected period.
Once the deadline passed, the window closed permanently for most claimants. The settlement website at www.riteaiddatasettlement.com was the official resource where victims could verify their eligibility and submit claims. The website included an FAQ section addressing common questions about the breach and the claims process. For individuals who believe they’re eligible but missed the deadline, contacting the Settlement Administrator through the official website is the only recourse available, and there’s no guarantee that late claims can be accommodated.
What Happens If You Missed the Claim Deadline
As of July 24, 2026, the original claim deadline is now nearly a year in the past. Victims who didn’t file a claim during the window cannot recover money through the settlement process.
This effectively excludes anyone who didn’t learn about the settlement or didn’t understand they were eligible in time to submit their claim. The practical consequence is that many victims lost the opportunity for compensation entirely. A person who experienced identity theft related to the Rite Aid breach but didn’t file a claim by July 7, 2025, has no recourse through this settlement, regardless of the actual damage they suffered.
Official Resources and Next Steps
The settlement information is documented at www.riteaiddatasettlement.com, where the FAQ page explains the breach details and settlement terms. The Settlement Administrator’s contact information is available through this official website.
Any inquiries about late claim procedures or the possibility of exceptions to the deadline must go through the Settlement Administrator, as no other organization has authority over this settlement. The court’s final approval hearing was scheduled for July 17, 2025, marking the official conclusion of the settlement approval process. With both preliminary and final approval phases complete, the settlement is active, though the claims window for most victims has closed.
- —
You Might Also Like
- Walgreens Prescription Privacy Class Action Claims: What Consumers Should Know
- Sam’s Club Delivery Fee Class Action Claims: What Consumers Should Know
- Costco Membership Auto-Renewal Class Action Claims: What Consumers Should Know