The Kroger data breach class action lawsuit stems from a 2021 cyberattack that exposed sensitive personal data belonging to thousands of Kroger customers and employees. If you shopped at Kroger or any of its subsidiary stores, your information may have been compromised.
This case has been working through the courts for years. In 2026, affected individuals are watching for settlement payouts and claim deadlines.
Here is everything you need to know: what happened, who qualifies, how much you could receive, and exactly how to file your claim before time runs out. One fact that catches most people off guard is that the breach did not originate from Kroger’s own systems.
A third-party vendor called Accellion was the entry point. That detail matters for your claim.
Kroger Data Breach Class Action Lawsuit Overview
The Kroger data breach class action lawsuit is a federal case alleging that Kroger failed to protect customer and employee data after a cyberattack on its third-party file transfer vendor, Accellion. Multiple lawsuits were filed starting in early 2021 and later consolidated.
Plaintiffs argue that Kroger was negligent. They say the company should have known that Accellion’s file transfer appliance had serious security vulnerabilities. Despite warnings in the cybersecurity community, Kroger continued using the outdated system.
The breach affected pharmacy customers, employees, and anyone whose data passed through Kroger’s Accellion-connected systems. Sensitive records like Social Security numbers, health information, and financial details were all exposed.
| Detail | Info |
|---|---|
| Case Origin | Early 2021 |
| Court | U.S. District Court, Southern District of Ohio |
| Defendant | The Kroger Co. |
| Root Cause | Accellion FTA vulnerability exploited by Clop ransomware group |
| Plaintiffs | Kroger customers and employees whose data was exposed |
The case was filed on behalf of a nationwide class. Think of it like a group complaint where thousands of affected people band together instead of suing individually. That collective pressure is what gives class actions their teeth.
Kroger initially downplayed the breach. But as more information surfaced about the scope of exposed data, public and legal pressure grew quickly.
Kroger Data Breach Settlement Details
The Kroger data breach settlement is an agreement reached between Kroger and the plaintiffs to resolve the class action claims without going to trial. Settlement negotiations have been a central focus of this case throughout 2025 and into 2026.
Under the proposed terms, Kroger agreed to establish a settlement fund to compensate affected class members. The fund covers out-of-pocket losses, time spent dealing with the breach, and credit monitoring services.

Kroger also agreed to improve its data security practices. This includes upgrading its vendor management protocols and discontinuing use of vulnerable third-party file transfer systems.
Key settlement terms include:
- A monetary fund for direct payments to qualifying class members
- Free credit monitoring and identity theft protection for a set period
- Reimbursement for documented out-of-pocket expenses related to the breach
- Kroger’s commitment to enhanced cybersecurity measures going forward
The settlement still required court approval. A fairness hearing was scheduled to give class members a chance to object or voice concerns before the judge signed off.
Not every class member will receive the same amount. Payouts depend on the type of harm you can document. Those with proof of identity theft or financial fraud tied to the breach stand to receive the most.
Kroger Data Breach Settlement Payout Breakdown
The Kroger data breach settlement payout varies based on the type of claim you file and the evidence you provide. There is no single flat payment for everyone.
Settlement payouts are typically divided into tiers. Each tier corresponds to a different level of harm.
| Claim Tier | Description | Estimated Payout Range |
|---|---|---|
| Tier 1: Basic | Data was exposed, no documented losses | $50 to $100 |
| Tier 2: Time Spent | Hours spent dealing with breach (password changes, monitoring, calls) | $100 to $250 |
| Tier 3: Out-of-Pocket | Documented financial losses (fraudulent charges, fees) | $250 to $1,000+ |
| Tier 4: Identity Theft | Confirmed identity theft directly linked to the breach | $1,000 to $5,000+ |
Think of it like an insurance claim. The more proof you bring to the table, the bigger your check. A receipt showing you paid for credit monitoring out of your own pocket carries weight. A police report for identity theft carries even more.
Class members without any documentation will likely receive the lowest tier payout. But they can still file. You do not need a lawyer. You do not need to have suffered catastrophic harm.
The total settlement fund is finite. If more people file claims, individual payouts could shrink. Early filing does not guarantee a bigger payout, but it does guarantee your spot.
Key Takeaway: The Kroger data breach class action arose from a preventable third-party vendor hack, and the settlement offers tiered payouts ranging from $50 for basic claims to $5,000 or more for confirmed identity theft cases.
Kroger Data Breach Lawsuit Update for 2026
As of 2026, the Kroger data breach lawsuit is in its settlement administration phase. The court has moved past initial motions and class certification.
The biggest development in 2026 is the claims window. Affected individuals now have a defined period to submit their claims before the deadline closes. Missing this window means forfeiting your right to compensation.
Here is a quick timeline of how this case has progressed:
| Year | Event |
|---|---|
| January 2021 | Accellion FTA breach discovered |
| February 2021 | Kroger confirms data exposure |
| March to June 2021 | Multiple class action lawsuits filed |
| 2022 | Cases consolidated in Southern District of Ohio |
| 2023 to 2024 | Discovery phase and class certification |
| 2025 | Settlement negotiations and preliminary approval |
| 2026 | Claims window open; fairness hearing; final approval expected |
The judge overseeing the case has been pushing both sides toward resolution. Kroger’s legal team has cooperated with settlement talks, which is generally a sign that payouts will move forward without major delays.
If final approval comes through in 2026, payments could begin arriving by late 2026 or early 2027. That timeline depends on how many claims are filed and whether any objections slow down the process.
Who Qualifies for the Kroger Data Breach Lawsuit
You qualify for the Kroger data breach lawsuit if your personal information was compromised as a result of the Accellion FTA breach that affected Kroger’s systems in early 2021. This includes both customers and employees.
Specifically, you may be a class member if you:
- Were a Kroger pharmacy customer whose health or prescription data was stored on the affected systems
- Were a Kroger employee or former employee whose HR records were exposed
- Received a data breach notification letter from Kroger in 2021
- Had personal data (Social Security number, date of birth, financial info) processed through Kroger’s Accellion file transfer system
You do not need to prove that your data was actually misused. The fact that it was exposed is enough to qualify you as a class member.
If you received a notification letter from Kroger, you are almost certainly in the class. That letter is your strongest piece of evidence. Keep it.
Even if you did not get a letter, you may still qualify. Some notifications were sent to outdated addresses or went to spam folders. Check with the claims administrator if you suspect your data was involved.
Kroger Data Breach Compensation Amounts Explained
Kroger data breach compensation amounts depend on what happened to your data and what you can prove. The settlement does not promise a guaranteed dollar figure to every class member.
There are three main categories of compensation:
Cash payments go to class members who file valid claims. These range from modest flat payments for basic exposure to larger reimbursements for documented financial harm.
Credit monitoring is offered free of charge for a set number of years. This typically includes identity theft insurance coverage as part of the package.
Out-of-pocket reimbursement covers expenses you already paid because of the breach. This could include credit monitoring services you purchased on your own, bank fees from fraudulent transactions, or costs associated with freezing and unfreezing your credit.
| Compensation Type | Details |
|---|---|
| Cash Payment (basic) | Flat amount for data exposure without losses |
| Cash Payment (documented) | Reimbursement for proven financial losses |
| Credit Monitoring | Multi-year free monitoring and identity theft insurance |
| Time Compensation | Payment for hours spent responding to the breach |
The biggest payouts go to people who experienced actual identity theft. If someone opened accounts in your name or filed fraudulent tax returns using your stolen data, those claims carry real dollar weight.
Save every receipt, every bank statement showing unauthorized charges, and every report you filed. Documentation is the difference between a small check and a meaningful one.
Kroger Data Breach Settlement Payout Per Person
The Kroger data breach settlement payout per person is estimated to range from $50 to over $5,000, depending on individual circumstances. Most class members without documented losses will fall at the lower end.
Here is the reality. In large data breach settlements, the per-person payout often lands below what people expect. When millions of people qualify and the fund is a fixed size, math works against big individual checks.
That said, this case involves sensitive data categories like health records and Social Security numbers. Courts tend to approve higher settlement values when the exposed information is particularly dangerous.
If you fall into Tier 1 (basic exposure, no documented harm), expect somewhere around $50 to $100. If you spent meaningful time dealing with the fallout and can log those hours, you could push into the $100 to $250 range.
For people with documented out-of-pocket losses, the ceiling rises significantly. And for confirmed identity theft victims with police reports and evidence tying the theft to this specific breach, payouts could exceed $5,000.
The final per-person amount will not be confirmed until the claims period closes and the court reviews the total number of valid claims filed against the settlement fund.
Key Takeaway: Most Kroger data breach class members will receive between $50 and $250, but victims of documented identity theft linked to the breach could receive $5,000 or more.
How to File a Kroger Data Breach Claim
Filing a Kroger data breach claim requires completing the official claim form and submitting it before the deadline. The process is straightforward and does not require a lawyer.
Here is a step-by-step breakdown:
- Get the claim form. The official form is available through the settlement administrator’s website. It was also mailed to known class members.
- Fill in your personal information. Name, address, contact details, and your unique class member ID (found on your notification letter).
- Select your claim category. Choose whether you are filing for basic exposure, time spent, out-of-pocket losses, or identity theft.
- Attach supporting documents. Bank statements, credit monitoring receipts, police reports, or breach notification letters.
- Submit before the deadline. You can submit online or by mail. Keep a copy of everything you send.
| Step | What to Do |
|---|---|
| 1 | Obtain claim form from settlement administrator |
| 2 | Enter personal and contact information |
| 3 | Select claim category |
| 4 | Upload or attach supporting documents |
| 5 | Submit before the filing deadline |
This is not a complex legal process. It is closer to filing a rebate than filing a lawsuit. The form takes about 15 to 20 minutes for most people.
One mistake to avoid: do not leave the documentation section blank if you have losses to report. A claim without supporting evidence gets the minimum payout. A claim with receipts and records gets significantly more.
Kroger Data Breach Filing Deadline
The Kroger data breach filing deadline is the final date by which all claims must be submitted to the settlement administrator. Missing this date means you lose your right to any payout from the settlement fund.
Based on the case timeline, the filing deadline is expected to fall in mid to late 2026. The exact date will be set by the court as part of the final approval order.
Here is what you need to know about the deadline:
- The deadline applies to both online and mailed claims
- Mailed claims must be postmarked by the deadline date, not received
- Late claims are almost never accepted, regardless of the reason
- You cannot file after the deadline even if you just discovered the breach
| Deadline Detail | Info |
|---|---|
| Expected Deadline | Mid to late 2026 |
| Submission Methods | Online or by mail |
| Late Claims | Not accepted |
| Postmark Rule | Mail must be postmarked by deadline |
Do not wait until the last week. Settlement websites can crash near deadlines. Mail can get delayed. Give yourself at least two weeks of cushion before the final date.
Set a calendar reminder right now. Seriously. People lose out on money they are owed because they keep telling themselves they will file tomorrow.
Kroger Data Breach Claim Form Guide
The Kroger data breach claim form is the official document you must complete to receive your portion of the settlement. It asks for identifying information, your connection to the breach, and details about your losses.
The form has several sections. Here is what each one asks for:
Section 1: Identification. Your full legal name, current mailing address, email, and phone number. If your name or address has changed since the breach, note both the old and new information.
Section 2: Class Member Verification. Your unique ID number from the breach notification letter. If you lost the letter, you can request a new ID from the claims administrator.
Section 3: Claim Type Selection. You pick which category applies to you. You can select more than one if applicable. For example, you can claim both time spent and out-of-pocket costs.
Section 4: Documentation Upload. This is where you attach proof. Accepted documents include:
- Kroger breach notification letter
- Bank or credit card statements showing fraud
- Receipts for credit monitoring purchases
- Police reports or FTC identity theft reports
- Phone or email records showing time spent resolving issues
Section 5: Certification and Signature. You sign under penalty of perjury that everything you stated is true. This is standard for all class action claims.
Double-check every field before submitting. Errors can delay your payout or get your claim rejected entirely.
Key Takeaway: The claim form is simple but requires attention to detail; attach every piece of supporting documentation you have, and submit well before the filing deadline to avoid losing your payout.
What Was the Kroger Accellion Data Breach
The Kroger Accellion data breach was a cyberattack that exploited a known vulnerability in Accellion’s File Transfer Appliance, a software tool Kroger used to send and receive sensitive files. The attack occurred in late December 2020 and January 2021.
Accellion’s FTA was an aging product. Security researchers had flagged it as outdated and vulnerable. Despite this, many large organizations, including Kroger, continued using it.

A cybercriminal group known as Clop exploited zero-day vulnerabilities in the FTA software. They broke in, extracted data, and then demanded ransom payments. When organizations refused to pay, Clop published stolen data on the dark web.
Kroger was one of dozens of organizations hit. Others included Shell, Stanford University, the Reserve Bank of New Zealand, and several government agencies. The scope was global.
| Detail | Info |
|---|---|
| Vulnerable Software | Accellion File Transfer Appliance (FTA) |
| Attack Timeframe | December 2020 to January 2021 |
| Threat Actor | Clop ransomware group |
| Method | Zero-day exploit of FTA vulnerabilities |
| Kroger’s Role | Used FTA for transmitting sensitive files |
Here is a simple way to think about it. Kroger hired a delivery service (Accellion) to move its sensitive files. That delivery service left the truck unlocked. Thieves broke in and grabbed everything inside. The lawsuit argues Kroger should have picked a better delivery service.
Accellion later rebranded itself as Kiteworks and retired the FTA product entirely. That decision came too late for the millions of people whose data was already stolen.
What Information Was Stolen in the Kroger Data Breach
The Kroger data breach exposed multiple categories of sensitive personal information. The specific data stolen varies by individual, depending on what type of records Kroger processed through the Accellion system.
Here is a breakdown of the types of information that were compromised:
- Social Security numbers of employees and some customers
- Names, addresses, and dates of birth
- Phone numbers and email addresses
- Pharmacy records and prescription information
- Health insurance details
- Financial account information
- HR and payroll data for Kroger employees
| Data Category | Who Was Affected |
|---|---|
| Social Security numbers | Employees and select customers |
| Pharmacy and prescription data | Kroger pharmacy customers |
| Financial information | Customers with Kroger financial accounts |
| HR and payroll records | Current and former Kroger employees |
| Health insurance data | Employees enrolled in Kroger health plans |
The pharmacy data is what makes this breach especially serious. Health information carries extra protections under federal law. When prescription records get exposed, it is not just a financial risk. It is a privacy violation that can affect someone’s employment, insurance, and personal relationships.
Not everyone had the same data exposed. Your breach notification letter should have specified what categories of your information were affected. If you did not receive a letter but suspect your data was involved, the claims administrator can verify your status.
Kroger Data Breach and Identity Theft Risks
The Kroger data breach created significant identity theft risks because it exposed the exact types of data that criminals use to steal identities: Social Security numbers, dates of birth, and financial account details. That combination is a goldmine for fraudsters.
If your Social Security number was in the stolen data, here is what could happen:
- Someone opens credit cards or loans in your name
- Fraudulent tax returns get filed using your SSN
- Medical identity theft, where someone uses your insurance for treatment
- Utility accounts opened in your name at addresses you have never lived at
These are not hypothetical threats. Data breach victims across the country have reported all of these outcomes after similar incidents.
Steps to protect yourself right now:
- Place a credit freeze with all three bureaus (Equifax, Experian, TransUnion)
- Set up fraud alerts on your credit reports
- Monitor your bank and credit card statements weekly
- File an identity theft report with the FTC if you see suspicious activity
- Enroll in the free credit monitoring offered through the settlement
A credit freeze is the single most effective step you can take. It prevents anyone from opening new accounts in your name. It is free. It takes about 10 minutes per bureau. And you can temporarily lift it whenever you need to apply for legitimate credit.
The risk does not go away after a year or two. Stolen Social Security numbers stay valuable to criminals for decades. Stay vigilant.
Key Takeaway: The Kroger breach exposed highly sensitive data including Social Security numbers and pharmacy records, creating long-term identity theft risks that every affected person should actively guard against with credit freezes and monitoring.
Which Kroger Subsidiaries Are Included in the Lawsuit
The Kroger data breach lawsuit covers not just Kroger-branded stores but also many of its subsidiary grocery chains across the country. If you shopped at or worked for any Kroger-owned store, you may be a class member.
Kroger is the largest supermarket chain in the United States. It operates under dozens of brand names that many customers do not realize are Kroger-owned.
Here are the major Kroger subsidiaries that may be covered:
| Subsidiary | Region |
|---|---|
| Harris Teeter | Southeast and Mid-Atlantic |
| Ralphs | Southern California |
| Fred Meyer | Pacific Northwest |
| King Soopers | Colorado |
| Fry’s Food Stores | Arizona |
| Smith’s Food and Drug | Intermountain West |
| QFC (Quality Food Centers) | Washington State |
| Dillons | Kansas |
| Baker’s Supermarkets | Nebraska |
| Pay Less Super Markets | Indiana |
| Mariano’s | Illinois |
| Pick ‘n Save | Wisconsin |
This is not a complete list. Kroger operates nearly 2,800 stores under roughly 24 different banners. If you are unsure whether your store is Kroger-owned, check the settlement notice or contact the claims administrator.
The key question is whether your store’s data flowed through the Accellion system. Not every subsidiary may have been affected. But Kroger’s centralized data infrastructure means many of them were connected to the same vulnerable pipeline.
How to Join the Kroger Data Breach Lawsuit
You can join the Kroger data breach lawsuit by filing a claim through the official settlement process. In most class actions, you are automatically included in the class unless you actively opt out.
Here is what that means in practical terms. If you are a class member (your data was exposed), you do not need to sign up or register to be part of the lawsuit itself. The class includes you by default.
What you do need to do is file a claim to receive money. Being part of the class does not automatically put a check in your mailbox. You must take action.
To participate and receive payment:
- Confirm your class member status through the settlement administrator
- Complete and submit the official claim form
- Provide documentation of any losses
- Submit everything before the filing deadline
If you want to opt out:
- You must submit a written opt-out request by the court-specified date
- Opting out means you get no settlement money
- But it preserves your right to file your own individual lawsuit against Kroger
Most people should stay in the class. Filing your own lawsuit is expensive, time-consuming, and risky. The class action settlement offers a simpler path to compensation.
One more thing. You do not need to hire your own attorney. The class action lawyers represent everyone in the class. Their fees come out of the settlement fund, not your pocket.
Kroger Data Breach Lawsuit Status and Next Steps
The Kroger data breach lawsuit status as of 2026 is in the settlement execution phase. The court has moved through class certification, and settlement terms are being finalized or have received preliminary approval.
Here is where things stand and what comes next:
| Phase | Status |
|---|---|
| Lawsuits Filed | Complete (2021) |
| Case Consolidation | Complete (2022) |
| Discovery | Complete (2023 to 2024) |
| Settlement Negotiations | Complete (2025) |
| Preliminary Approval | Granted or pending (2025 to 2026) |
| Claims Window | Open (2026) |
| Fairness Hearing | Scheduled for 2026 |
| Final Approval | Expected 2026 |
| Payouts Begin | Late 2026 or early 2027 |
The fairness hearing is a critical step. This is where the judge listens to any objections from class members and decides whether the settlement is fair, reasonable, and adequate. If no major objections arise, final approval typically follows within a few months.
After final approval, the claims administrator processes all submitted claims, verifies eligibility, calculates individual payouts, and distributes checks or direct deposits.
What you should do right now:
- File your claim if you have not already
- Gather all documentation of losses
- Watch for court notices about the fairness hearing date
- Set a reminder for the filing deadline
The finish line is close. But you only cross it if you actually file your claim.
Key Takeaway: The Kroger data breach lawsuit is in its final phases in 2026, with the claims window open and payouts expected to begin by late 2026 or early 2027 for those who file before the deadline.
Frequently Asked Questions
How much money will I get from the Kroger data breach settlement?
Most class members will receive between $50 and $250 for basic claims.
If you have documented out-of-pocket losses or confirmed identity theft, payouts could reach $1,000 to $5,000 or more.
The exact amount depends on your claim tier and the total number of claims filed.
Am I eligible for the Kroger data breach class action lawsuit?
You are eligible if your personal information was exposed in the Accellion FTA breach that affected Kroger’s systems in early 2021.
This includes Kroger customers, pharmacy patients, and current or former employees.
Receiving a breach notification letter from Kroger is the strongest indicator of eligibility.
What is the deadline to file a Kroger data breach claim?
The filing deadline is expected to fall in mid to late 2026.
The exact date will be confirmed in the court’s final approval order.
Do not wait until the last minute, as late claims are not accepted.
What personal information was exposed in the Kroger data breach?
The breach exposed Social Security numbers, names, addresses, dates of birth, pharmacy records, health insurance information, and financial data.
The specific data compromised varies by individual.
Your breach notification letter should list which categories of your data were affected.
Do I need a lawyer to join the Kroger data breach lawsuit?
No, you do not need your own lawyer.
The class action attorneys represent all class members, and their fees come from the settlement fund.
You simply need to file the claim form before the deadline to participate.
The Kroger data breach class action lawsuit gives affected customers and employees a real chance at compensation in 2026. The claims window is open, and the process is straightforward.
If your data was exposed, do not sit on this. File your claim, attach your documentation, and beat the deadline.
Your information was compromised through no fault of your own. The settlement exists to make that right






