Supply chain ⛓ Supply Chain

Dollar Tree/Family Dollar — Zeroed-In Technologies Breach (1.98M)

📅 2023-08-07 🏢 Zeroed-In Technologies HR analytics platform
Primary Source ↗

Incident Details

Dollar Tree and its subsidiary Family Dollar disclosed in November 2023 that Zeroed-In Technologies, a third-party HR analytics vendor they used, suffered a data breach between August 7–8, 2023. Approximately 1.98 million individuals were notified — primarily current and former Dollar Tree and Family Dollar employees. The stolen data included names and Social Security numbers. Zeroed-In Technologies provides workforce analytics software used by retail companies to analyze employee data. The breach occurred at the vendor level; Dollar Tree/Family Dollar systems were not directly breached. This was one of several notable third-party vendor breaches in the retail sector in 2023, illustrating the ongoing supply chain exposure created by sharing sensitive employee data with HR technology vendors.

Technical Details

Initial Attack Vector
Zeroed-In Technologies, an HR analytics vendor used by Dollar Tree and Family Dollar, suffered a data breach affecting its systems — attackers accessed systems and stole employee data; Dollar Tree and its subsidiary Family Dollar were downstream victims
Vendor / Product
Zeroed-In Technologies HR analytics platform
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2023-08-07 Breach occurred
  2. 2023-11-20 Publicly disclosed
  3. 2023-11-28 Customers notified