Supply chain
⛓ Supply Chain
Dollar Tree/Family Dollar — Zeroed-In Technologies Breach (1.98M)
Primary Source ↗Incident Details
Dollar Tree and its subsidiary Family Dollar disclosed in November 2023 that Zeroed-In Technologies, a third-party HR analytics vendor they used, suffered a data breach between August 7–8, 2023. Approximately 1.98 million individuals were notified — primarily current and former Dollar Tree and Family Dollar employees. The stolen data included names and Social Security numbers. Zeroed-In Technologies provides workforce analytics software used by retail companies to analyze employee data. The breach occurred at the vendor level; Dollar Tree/Family Dollar systems were not directly breached. This was one of several notable third-party vendor breaches in the retail sector in 2023, illustrating the ongoing supply chain exposure created by sharing sensitive employee data with HR technology vendors.
Technical Details
- Initial Attack Vector
- Zeroed-In Technologies, an HR analytics vendor used by Dollar Tree and Family Dollar, suffered a data breach affecting its systems — attackers accessed systems and stole employee data; Dollar Tree and its subsidiary Family Dollar were downstream victims
- Vendor / Product
- Zeroed-In Technologies HR analytics platform
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2023-08-07 Breach occurred
- 2023-11-20 Publicly disclosed
- 2023-11-28 Customers notified