Yes, approximately 2.2 million Rite Aid customers affected by the pharmacy’s June 2024 data breach were eligible to file claims in a $6.8 million settlement—but the deadline to submit claims has already passed. The claim filing window closed on July 7, 2025, meaning anyone who did not submit a claim by that date can no longer participate in the settlement. If you filled out a claim form and received a Notice ID and Confirmation Code from Rite Aid’s breach notification, you may already be part of the settlement distribution. If you never filed, you are ineligible to recover compensation from this particular lawsuit, regardless of whether you were affected.
The settlement resolved a class action lawsuit filed against Rite Aid following a ransomware attack that exposed names, addresses, dates of birth, driver’s license numbers, and other ID documents presented at purchase. The U.S. District Court for the Eastern District of Pennsylvania granted final approval to the settlement on July 30, 2025, after preliminary approval in March 2025. This means the settlement is now locked in place, and distributions to those who filed valid claims are proceeding or have already occurred.
Table of Contents
- What Personal Information Did Rite Aid Lose in the Data Breach?
- Who Qualified for the Rite Aid Settlement and Why the Eligibility Window Matters?
- How Much Compensation Was Available in the Settlement?
- How Did Claimants Submit Their Claims Before the Deadline Expired?
- What Obligations Did Rite Aid Accept as Part of the Settlement?
- Timeline of the Breach Discovery and Settlement Process
- Lessons for People Who May Have Missed This Settlement or Similar Ones
What Personal Information Did Rite Aid Lose in the Data Breach?
On June 6, 2024, an unauthorized third party gained access to rite Aid’s systems by impersonating a company employee. The breach was discovered on June 20, 2024—just 12 hours after the initial unauthorized access—but by that time, the threat actor, identified as the RansomHub ransomware group, had already exfiltrated customer data. The company’s quick detection prevented further damage, but the data was already compromised and beyond recovery.
The stolen information included names, residential addresses, dates of birth, driver’s license numbers, and copies of other ID documents that customers presented when making purchases. This combination of data is particularly dangerous because it contains the exact elements identity thieves need to open fraudulent accounts, file false tax returns, or apply for credit in someone else’s name. The breach affected only customers who presented ID at the time of purchase during a specific window: June 6, 2017 through July 30, 2018. Customers who paid without showing ID during those years were not part of the affected population.
Who Qualified for the Rite Aid Settlement and Why the Eligibility Window Matters?
To be eligible for the settlement, you had to meet three criteria: you were a U.S. resident, your personal information was exposed in the breach, and you made a purchase at Rite Aid during the vulnerable period from June 6, 2017 to July 30, 2018 while presenting an ID. Not all Rite Aid customers from that era qualified—only those whose ID information was actually captured and subsequently stolen were included in the 2.2 million-person class. This limitation is a critical distinction because millions of people shopped at Rite Aid during those years, yet only a fraction had their driver’s licenses or ID documents recorded and later compromised.
A major limitation of this settlement is that even if you were affected, you had to know about it and act before July 7, 2025. Rite Aid sent breach notification letters to customers whose addresses were on file, but not every affected customer received notice. If you moved, had an outdated address with the pharmacy, or did not check your mail carefully, you may not have seen the settlement deadline in time. The settlement website (riteaiddatasettlement.com) allowed people who didn’t receive the notification to call 833-421-7672 for assistance, but that option is also now closed since the deadline has expired.
How Much Compensation Was Available in the Settlement?
The $6.8 million settlement fund was divided into two compensation tracks. The first track was for class members who could document their losses from identity theft or fraud related to the breach. These individuals could claim reimbursement for specific, documented expenses up to a maximum of $10,000. Eligible expenses included identity theft costs (such as fees paid to identity theft recovery services), fraudulent charges made in their names, credit monitoring fees incurred after June 6, 2024, and professional identity restoration services.
To prove losses, claimants had to submit bank statements, identity theft reports, credit reports showing fraudulent accounts, or police reports of fraud—not just say they were harmed. The second track was for class members without documented losses or who could not provide supporting documentation. These people received a pro-rata share of whatever funds remained after documented-loss claims were paid out. If everyone who filed received their full $10,000 request, there would be money left over for the cash-only group; if documented claims consumed most of the fund, the pro-rata payments to the second group would be smaller. A person who suffered identity theft but had no receipts or proof might receive only a few hundred dollars through the cash-fund track instead of thousands through the documented-loss track—a significant gap that penalized those without organized financial records.
How Did Claimants Submit Their Claims Before the Deadline Expired?
Before July 7, 2025, eligible class members could file claims online at riteaiddatasettlement.com using a Notice ID and Confirmation Code from their breach notification letter. The online process was straightforward for those with documentation in hand: upload bank statements, police reports, identity theft affidavits, or credit monitoring invoices showing charges after June 6, 2024. Alternatively, claimants could download a claim form from the settlement website and mail it along with photocopies of supporting documents to the claims administrator.
For people who had not received the breach notification letter, the settlement provided a phone line, 833-421-7672, staffed through the settlement period. Callers without a Notice ID could work with a representative to verify their eligibility and receive claim forms by mail. However, all of these filing methods required submission by July 7, 2025. Anyone who intended to claim compensation but delayed, lost the notification letter, or simply did not know about the settlement forfeited their right to participate.
What Obligations Did Rite Aid Accept as Part of the Settlement?
Although Rite Aid denied any wrongdoing in the settlement agreement, the company did agree to implement enhanced cybersecurity measures going forward. The specifics of these security improvements were not detailed in public filings, but the settlement required Rite Aid to take additional steps to protect customer data against similar breaches in the future. The fact that the company made this commitment while simultaneously filing for bankruptcy illustrates how serious the settlement dispute was—even in financial distress, Rite Aid’s legal team determined that defending the lawsuit was costlier than settling.
One critical limitation is that Rite Aid’s bankruptcy proceedings did not prevent the settlement from being reached or funded. The settlement amount of $6.8 million was carved out and protected as part of the bankruptcy process, ensuring that affected customers received compensation even as the company restructured its business. However, this also meant that the settlement was the only avenue for recovery; class members could not pursue separate lawsuits against Rite Aid for the same breach once the settlement was approved.
Timeline of the Breach Discovery and Settlement Process
The full sequence of events unfolded rapidly but with a crucial gap for claimants. The breach occurred on June 6, 2024, and was discovered on June 20, 2024. Rite Aid notified affected customers and launched an investigation. On March 4, 2025, the court granted preliminary approval to the settlement, which meant both sides agreed in principle and the settlement was deemed fair and adequate.
A six-month window for claims then opened, extending from March through July 2025. Final approval came on July 30, 2025, one day after the deadline for submitting new claims closed. At that point, no additional claims could be accepted, and the court locked in the settlement distribution. For claimants, this timeline created urgency—there were only four months between preliminary approval and the claim deadline to gather documentation, complete forms, and submit claims. People who received their breach notification late or those who did not immediately act had limited time to assemble proof of expenses.
Lessons for People Who May Have Missed This Settlement or Similar Ones
If you received a Rite Aid breach notification letter but did not file a claim by July 7, 2025, that deadline cannot be extended. The settlement is now closed to new claimants, and distributions are being processed or have already been completed for those who timely filed. The only recourse for people in this situation is to monitor their credit reports for fraudulent activity and take protective steps like placing a fraud alert or credit freeze if they detect suspicious accounts. For future data breaches and settlements, the lesson is clear: claim deadlines in class action settlements are absolute.
Even if you believe you qualify, if you miss the filing date, you lose the opportunity. Keep breach notification letters in a safe place, set calendar reminders for the deadline date, and file claims early rather than waiting until the last minute. Some settlements offer 6-12 months for claims, but others compress the window to just 3-4 months. The Rite Aid settlement’s tight timeline meant that procrastination resulted in permanent loss of compensation rights.
- —
