Company Details
sam's-club
47,591
409,679
43
samsclub.com
1271
SAM_1414288
Completed


Sam's Club Vendor Cyber Rating & Cyber Score
samsclub.comSam’s Club (Nasdaq: WMT) a division of Walmart Inc., is the membership warehouse club solution for everyday living. Our President and CEO is Chris Nicholas and our headquarters is in Bentonville, AR. For the fiscal year ending January 31, 2023, Sam’s Club’s total revenue was $84.3 billion. There are almost 600 clubs across the U.S and Puerto Rico and each averages approximately 136,000 square feet. Our first club opened in Midwest City, Oklahoma, in 1983. Many clubs include sustainable features such as day-lighting with skylights, night dimming, central energy management, water-conserving fixtures, natural concrete floors and recycling. Sam’s Club employs thousands of associates in the U.S. and Puerto Rico. Approximately 75 percent of club management was promoted from hourly positions. In addition to the leading national brands, Sam's Club also features Member's Mark, an exclusive, premium-quality private brand. Member's Mark products are exclusive designs that use top-of-the-line materials and the highest quality ingredients to make sure they have the best quality and value at members-only prices. A Sam’s Club membership can more than pay for itself with exclusive savings on the items you need, the items you love and all sorts of unexpected items. Sam’s Club focuses on providing members with exclusive savings and quality merchandise, as well as services like Delivery from Club and Curbside Pickup, savings on fuel, full-service Pharmacy and more. We offer our members the most choices on how to shop with us, anywhere, any time. With over 40 years of innovating in the category, Sam’s Club continues to redefine club membership shopping with its curated assortment of quality fresh food and Member’s Mark® items, in addition to market leading technologies and services like Scan & Go™️, curbside pickup and home delivery. Visit the Sam's Club Newsroom, shop at SamsClub.com or connect with Sam's Club on LinkedIn, X, Facebook, Instagram, TikTok and Pinterest.
Company Details
sam's-club
47,591
409,679
43
samsclub.com
1271
SAM_1414288
Completed
Between 700 and 749

Sam's Club Global Score (TPRM)XXXX

Description: In mid-November, Sam’s Club reported a data breach where unauthorized individuals gained access to customer accounts using credentials likely obtained from an external source. The incident exposed sensitive personal information, including names, phone numbers, postal addresses, and payment card details. While the exact number of affected customers remains undisclosed, the breach poses significant risks such as identity theft, financial fraud, and reputational damage. The compromised payment card data could lead to fraudulent transactions, while the exposure of personal details increases the likelihood of targeted phishing or social engineering attacks. The breach underscores vulnerabilities in credential security and the potential for cascading harm when third-party credentials are reused across platforms. Customers are advised to monitor their accounts for suspicious activity and update their login credentials to mitigate further risks.
Description: The California Office of the Attorney General disclosed a data breach targeting Sam's Club in October 2020, stemming from an incident on September 24, 2020. Unauthorized actors gained access to member accounts using stolen login credentials, compromising personal information of affected individuals. While the exact scope of exposed data was not detailed, such breaches typically involve sensitive details like names, contact information, membership IDs, or payment data posing risks of identity theft, phishing, or financial fraud. The breach underscored vulnerabilities in credential security, highlighting the need for stronger authentication measures. Sam’s Club likely faced reputational damage and potential regulatory scrutiny, though no evidence suggested systemic operational disruption or ransomware involvement. Customers were advised to monitor accounts and update passwords, but the long-term impact on trust and membership retention remained a concern.
Description: Sam's Club, a subsidiary of Walmart, is investigating a potential security incident following claims of a breach by the Clop ransomware gang. Clop has added Sam's Club to its leak site but has not yet released proof. The breach may involve the exploitation of a zero-day vulnerability in Cleo file transfer software, which Sam's Club may have used. Prior incidents include credential stuffing in 2020, but the current situation remains under investigation with no explicit customer or employee data known to be compromised.


No incidents recorded for Sam's Club in 2026.
No incidents recorded for Sam's Club in 2026.
No incidents recorded for Sam's Club in 2026.
Sam's Club cyber incidents detection timeline including parent company and subsidiaries

Sam’s Club (Nasdaq: WMT) a division of Walmart Inc., is the membership warehouse club solution for everyday living. Our President and CEO is Chris Nicholas and our headquarters is in Bentonville, AR. For the fiscal year ending January 31, 2023, Sam’s Club’s total revenue was $84.3 billion. There are almost 600 clubs across the U.S and Puerto Rico and each averages approximately 136,000 square feet. Our first club opened in Midwest City, Oklahoma, in 1983. Many clubs include sustainable features such as day-lighting with skylights, night dimming, central energy management, water-conserving fixtures, natural concrete floors and recycling. Sam’s Club employs thousands of associates in the U.S. and Puerto Rico. Approximately 75 percent of club management was promoted from hourly positions. In addition to the leading national brands, Sam's Club also features Member's Mark, an exclusive, premium-quality private brand. Member's Mark products are exclusive designs that use top-of-the-line materials and the highest quality ingredients to make sure they have the best quality and value at members-only prices. A Sam’s Club membership can more than pay for itself with exclusive savings on the items you need, the items you love and all sorts of unexpected items. Sam’s Club focuses on providing members with exclusive savings and quality merchandise, as well as services like Delivery from Club and Curbside Pickup, savings on fuel, full-service Pharmacy and more. We offer our members the most choices on how to shop with us, anywhere, any time. With over 40 years of innovating in the category, Sam’s Club continues to redefine club membership shopping with its curated assortment of quality fresh food and Member’s Mark® items, in addition to market leading technologies and services like Scan & Go™️, curbside pickup and home delivery. Visit the Sam's Club Newsroom, shop at SamsClub.com or connect with Sam's Club on LinkedIn, X, Facebook, Instagram, TikTok and Pinterest.


At Costa Coffee, we’ve been crafting with heart and changing the coffee game since 1971. Now part of The Coca-Cola Company, we proudly operate in over 50 countries, and we’re still growing! And we’re much more than our beloved stores. Consumers all over the world can now enjoy Costa Coffee in our Re

Our team of friendly faces works as one to provide shopping trips and a career experience you won’t find anywhere else. Together we work the Morrisons way. Constantly looking to do things even better, we work in partnership with our communities, colleagues, suppliers and British farmers to provide

Coles is one of Australia’s leading retailers, with an extensive footprint of over 1,800 retail outlets nationally. We employ more than 115,000 team members, engage with more than 8,000 suppliers, and we welcome millions of customers through our store network and digital platforms every week. We ar

Mercadona is a leading company of physical supermarkets in Spain with an online service, with over 1,610 stores and more than 5.9 million households as customers. Additionally, it has 60 stores in Portugal, with a presence in nine different districts. A family-owned company, its objective is to off
Macy's is America’s store for life. The largest retail brand of Macy's, Inc. (NYSE:M) delivers quality fashion at affordable prices to customers at approximately 640 locations in 43 states, the District of Columbia, Puerto Rico, and Guam, as well as to customers in more than 100 international destin

At Sunbelt Rentals, we provide the tools, equipment, and support our customers need to build and maintain the world around us. With locations across the U.S. and Canada and a team of passionate experts, we're here to ensure our customers have what they need to get the job done right—safely, efficie

Since arriving in the UK in 1990, we’ve gone on to be one of the biggest (and the highest-paying) supermarkets in the game, with a team of 45,000 colleagues who make Everyday Amazing. We've been crowned the 'Retail Employer of the Year' at the Grocer Gold Awards four times, which is a testament to

Jumbo is een Brabants familiebedrijf met een rijke historie. Begonnen in 1921 als levensmiddelengroothandel heeft Jumbo een indrukwekkende groei doorgemaakt. Inmiddels is het de tweede supermarktketen van Nederland. Wekelijks verwelkomt Jumbo miljoenen klanten in meer dan 700 winkels en online via J

Coppel es una empresa mexicana con sede en la ciudad de Culiacán, que ha sido fundada en 1941. Es una cadena comercial de tiendas departamentales de ventas a través del otorgamiento de créditos con pocos requisitos, y repartos gratuitos. En la actualidad cuenta con mas de 1000 puntos de venta, distr
.png)
Stacey Tinsley, Bossier Press-Tribune. Members of the Bossier City Lions Club welcomed Charlene Cooper, director of CYBER.
Cybersecurity firm Bitdefender said on Tuesday it had uncovered a wave of online scams using near-identical sites to the official Milano Cortina 2026...
New York Tech-Vancouver students achieved a significant milestone at CyberSci 2025, earning third place in the Vancouver region and 25th...
Hacker's Movie Guide” with Foreword by Steve Wozniak, co-founder of Apple.
The U.S. government faces another funding lapse in Trump's second term, posing a threat to federal agencies and services.
A team of computer science students from Washington State University earned national recognition in the Cyber Power Rankings.
United Natural Foods (UNFI) has informed law enforcement and is working to mitigate the attack's impact with the help of cybersecurity...
United Natural Foods (UNFI), North America's largest publicly traded wholesale distributor, was forced to shut down some systems following a recent cyberattack.
A consumer dropped her lawsuit against Sam's Club and software provider Cleo Communications US LLC over a data breach linked to a vulnerability in Cleo's file-...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Sam's Club is http://www.samsclub.com.
According to Rankiteo, Sam's Club’s AI-generated cybersecurity score is 739, reflecting their Moderate security posture.
According to Rankiteo, Sam's Club currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Sam's Club has not been affected by any supply chain cyber incidents, and no incident IDs are currently listed for the organization.
According to Rankiteo, Sam's Club is not certified under SOC 2 Type 1.
According to Rankiteo, Sam's Club does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Sam's Club is not listed as GDPR compliant.
According to Rankiteo, Sam's Club does not currently maintain PCI DSS compliance.
According to Rankiteo, Sam's Club is not compliant with HIPAA regulations.
According to Rankiteo,Sam's Club is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Sam's Club operates primarily in the Retail industry.
Sam's Club employs approximately 47,591 people worldwide.
Sam's Club presently has no subsidiaries across any sectors.
Sam's Club’s official LinkedIn profile has approximately 409,679 followers.
Sam's Club is classified under the NAICS code 43, which corresponds to Retail Trade.
No, Sam's Club does not have a profile on Crunchbase.
Yes, Sam's Club maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/sam's-club.
As of April 02, 2026, Rankiteo reports that Sam's Club has experienced 3 cybersecurity incidents.
Sam's Club has an estimated 15,730 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Ransomware and Breach.
Title: Potential Security Incident at Sam's Club
Description: Sam's Club, a subsidiary of Walmart, is investigating a potential security incident following claims of a breach by the Clop ransomware gang. Clop has added Sam's Club to its leak site but has not yet released proof. The breach may involve the exploitation of a zero-day vulnerability in Cleo file transfer software, which Sam's Club may have used. Prior incidents include credential stuffing in 2020, but the current situation remains under investigation with no explicit customer or employee data known to be compromised.
Type: Ransomware
Attack Vector: Zero-day vulnerability exploitation
Vulnerability Exploited: Cleo file transfer software
Threat Actor: Clop ransomware gang
Title: Sam's Club Data Breach (2020)
Description: The California Office of the Attorney General reported a data breach involving Sam's Club on October 21, 2020. The breach occurred on September 24, 2020, due to unauthorized access to accounts using stolen login credentials, potentially affecting various personal information of members.
Date Detected: 2020-09-24
Date Publicly Disclosed: 2020-10-21
Type: Data Breach
Attack Vector: Unauthorized Access (Stolen Credentials)
Common Attack Types: The most common types of attacks the company has faced is Breach.
Identification of Attack Vectors: The company identifies the attack vectors used in incidents through Compromised credentials (likely from another source) and Stolen Login Credentials.

Data Compromised: Personal information
Identity Theft Risk: Potential
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Personally Identifiable Information (Pii), Payment Card Information, , Personal Information and .

Entity Name: Sam's Club
Entity Type: Retail
Industry: Retail / Wholesale
Location: United States (California)

Type of Data Compromised: Personal information
Personally Identifiable Information: Potential

Ransomware Strain: Clop

Regulatory Notifications: California Office of the Attorney General

Source: California Office of the Attorney General
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: California Office of the Attorney General.

Investigation Status: Under investigation

Entry Point: Stolen Login Credentials

Root Causes: Unauthorized Access Via Stolen Credentials,
Last Attacking Group: The attacking group in the last incident was an Clop ransomware gang.
Most Recent Incident Detected: The most recent incident detected was on 2020-09-24.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2020-10-21.
Most Significant Data Compromised: The most significant data compromised in an incident were Names, Phone Numbers, Postal Addresses, Payment Card Details, , Personal Information and .
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Phone Numbers, Payment Card Details, Names, Postal Addresses and Personal Information.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 0.
Most Recent Source: The most recent source of information about an incident is California Office of the Attorney General.
Current Status of Most Recent Investigation: The current status of the most recent investigation is Under investigation.
Most Recent Entry Point: The most recent entry point used by an initial access broker were an Stolen Login Credentials and Compromised credentials (likely from another source).
.png)
A vulnerability was found in Nothings stb up to 1.26. Impacted is the function stbtt_InitFont_internal in the library stb_truetype.h of the component TTF File Handler. Performing a manipulation results in out-of-bounds read. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read in VS6ComFile!get_macro_mem_COM. Opening a crafted V7 file may lead to information disclosure from the affected product.
V-SFT versions 6.2.10.0 and prior contain a stack-based buffer overflow in VS6ComFile!CSaveData::_conv_AnimationItem. Opening a crafted V7 file may lead to arbitrary code execution on the affected product.
V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in VS6MemInIF!set_temp_type_default. Opening a crafted V7 file may lead to information disclosure from the affected product.
V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in VS6ComFile!load_link_inf. Opening a crafted V7 file may lead to information disclosure from the affected product.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.