Petco Customer Data Exposed in Vermont Filing, Monitoring Underway
Petco Animal Supplies Stores, Inc. reported a data security incident to the Vermont Attorney General on September 10, 2026, affecting various customer data points. The exposed information includes names, contact details, payment card data, and loyalty account specifics. Individuals should review their accounts and take protective measures to safeguard their information.
- State
- Vermont
- Reported
- September 10, 2026
What may have been exposed
- Full Name
- Email Address
- Mailing Address
- Phone Number
- Password or Credential Hash
- Purchase and Order History
- Payment Card Information
- Loyalty Account Details
Petco Animal Supplies Stores, Inc. formally disclosed a data security incident to the Vermont Attorney General's office on September 10, 2026. The nature of the breach remains unspecified in public filings, and the investigation into the incident is currently listed as monitoring.
The reported exposed data categories are extensive, according to regulatory filings. These include Full Name, Email Address, Mailing Address, Phone Number, Password or Credential Hash, Purchase and Order History, Payment Card Information, and Loyalty Account Details. These data points were identified as potentially compromised during the incident.
Exposure of this combination of personal and financial information carries notable risks for affected individuals. Unauthorized actors could potentially use details like email addresses and password hashes to attempt unauthorized access to other online accounts. Purchase history could be leveraged for targeted phishing attempts, while payment card information could lead to fraudulent transactions.
To help mitigate potential risks, individuals who believe they may be affected are encouraged to take proactive steps. It is advisable to change passwords for any online accounts that may share credentials with Petco and to enable multi-factor authentication wherever possible. Regularly reviewing financial statements and monitoring credit reports for any suspicious activity is also a critical precaution.
Additionally, vigilance against unexpected communications, such as emails or text messages, is recommended. Scammers often use data obtained from breaches to craft convincing phishing attempts. Verifying the legitimacy of any unusual requests directly with the company through official channels, rather than clicking on links in suspicious messages, is a strong defense.
Source: Vermont Attorney General filing