Company Details
family-dollar
101,015
148,141
43
familydollar.com
0
FAM_9091707
In-progress

Family Dollar Company CyberSecurity Posture
familydollar.comWhen it comes to getting value for everyday items for the entire family in an easy to shop, neighborhood location, Family Dollar is the best place to go. One of the nation’s fastest growing retailers, Family Dollar offers a compelling assortment of merchandise for the whole family ranging from household cleaners to name brand foods, from health and beauty aids to toys, from apparel for every age to home fashions, all for everyday low prices. While shoppers can find many items at $1 or less, most items in the store are priced below $10, which makes shopping fun without stretching the family budget. As shoppers enter their neighborhood Family Dollar, they’ll find great values on the name brands they trust in a clean, well-organized store staffed with friendly team members who are members of the local community. The average size of a Family Dollar store is approximately 7,000 square feet, and most stores are operated in leased facilities. This relatively small footprint allows the Company to open new stores in rural areas and small town, as well as in large urban neighborhoods. Within these markets, the stores are located in shopping centers or as free-standing building and all are convenient to the Company’s customer base. Family Dollar offers a compelling mix of merchandise for the whole family. Ranging from an expanded assortment of refrigerated and frozen foods and health and beauty items to home décor and seasonal items, Family Dollar offers the lowest possible price, the name brand and quality private-brand merchandise customers need and use every day.
Company Details
family-dollar
101,015
148,141
43
familydollar.com
0
FAM_9091707
In-progress
Between 800 and 849

Family Dollar Global Score (TPRM)XXXX

Description: The INC Ransomware group claimed responsibility for a data breach at **Dollar Tree**, alleging the theft of **1.2TB of sensitive and personal data**, including **passport copies, payroll forms, job letters, legal correspondence, and complaints involving sexual harassment and discrimination cases**. The leaked data primarily pertains to **former employees of 99 Cents Only Stores**, a separate entity from which Dollar Tree acquired only real estate lease rights—not its systems or data. Despite Dollar Tree’s denial of direct involvement, the ransomware group insists the breach is tied to the company. INC Ransomware, known for **double-extortion tactics**, has previously targeted high-profile victims like **Ahold Delhaize (6TB stolen) and the UK’s NHS**, demanding ransoms exceeding **$5 million**. The group operates with **sophisticated malware**, often rebranding (e.g., as *Lynx*) while maintaining aggressive extortion strategies. The breach underscores escalating cyber threats against major corporations, with **employee data exposure** posing reputational, legal, and operational risks. Dollar Tree’s response emphasizes the data’s origin from 99 Cents Only Stores, but the incident highlights vulnerabilities in third-party associations.


No incidents recorded for Family Dollar in 2025.
No incidents recorded for Family Dollar in 2025.
No incidents recorded for Family Dollar in 2025.
Family Dollar cyber incidents detection timeline including parent company and subsidiaries

When it comes to getting value for everyday items for the entire family in an easy to shop, neighborhood location, Family Dollar is the best place to go. One of the nation’s fastest growing retailers, Family Dollar offers a compelling assortment of merchandise for the whole family ranging from household cleaners to name brand foods, from health and beauty aids to toys, from apparel for every age to home fashions, all for everyday low prices. While shoppers can find many items at $1 or less, most items in the store are priced below $10, which makes shopping fun without stretching the family budget. As shoppers enter their neighborhood Family Dollar, they’ll find great values on the name brands they trust in a clean, well-organized store staffed with friendly team members who are members of the local community. The average size of a Family Dollar store is approximately 7,000 square feet, and most stores are operated in leased facilities. This relatively small footprint allows the Company to open new stores in rural areas and small town, as well as in large urban neighborhoods. Within these markets, the stores are located in shopping centers or as free-standing building and all are convenient to the Company’s customer base. Family Dollar offers a compelling mix of merchandise for the whole family. Ranging from an expanded assortment of refrigerated and frozen foods and health and beauty items to home décor and seasonal items, Family Dollar offers the lowest possible price, the name brand and quality private-brand merchandise customers need and use every day.


Walmart Canada operates a chain of more than 400 stores nationwide serving 1.5 million customers each day. Walmart Canada's flagship online store, Walmart.ca is visited by more than 1.5 million customers daily. With more than 100,000 associates, Walmart Canada is one of Canada's largest employers an

YOU LIVE AND BREATHE SPORTS. SO DO WE. In work and in life. On the field, the court or the ice. Nothing wins like a commitment to excellence; to your team and your goals. At DICK’S Sporting Goods, it’s this kind of thinking that inspires our mission. Our culture is the result of people who give t

Coles Group is home to some of Australia’s iconic and most trusted brands and is one of the biggest employers with more than 1115,000 team members in every state and territory. Our workforce is diverse including groceries and liquor retail operations, online, manufacturing, cleaning and trolley serv

Founded in 1960 in North Carolina, Harris Teeter has been enriching the lives of our customers and our communities for decades. Today, Harris Teeter employs 36,000 valued associates and operates more than 250 stores and 70 fuel centers in seven states and the District of Columbia. In addition to our

At H&M, we welcome you to be yourself and feel like you truly belong. Help us reimagine the future of an entire industry by making everyone look, feel, and do good. We take pride in our history of making fashion accessible to everyone and led by our values we strive to build a more welcoming, inclu

Lowe’s Companies, Inc. (NYSE: LOW) is a FORTUNE® 50 home improvement company serving approximately 20 million customers a week in the United States. Lowe’s and its related businesses operate or service more than 2,200 home improvement and hardware stores and employ over 300,000 associates. Based in

Ahold Delhaize is one of the world’s largest food retail groups, we are a leader in supermarkets and e-commerce, and a company at the forefront of sustainable retailing. Our local brands employ around 393,000 associates in around 9,400 local grocery, small format, and specialty stores. Our family

Apparel Group is a multi-award-winning global fashion and lifestyle retail conglomerate based in Dubai, UAE, with operations across the GCC. Today, Apparel Group caters to millions of eager shoppers through its 2,300+ retail stores and 85+ brands on all platforms while employing over 24,000 multicul
Charlotte-based Belk, Inc., a privately-owned department store, began when William Henry Belk opened his first store in 1888 with his brother, Dr. John Belk, joining as a partner. What started as two brothers in business has now grown into a legacy of selling great products at great prices, treating
.png)
Do you think America is vulnerable to a cybersecurity crisis? Vote in the poll above or click here. A web company's technical issues this...
Mike was named Chief Executive Officer in December 2024. He joined Dollar Tree as Chief Operating Officer in October 2022 with...
Phantom Hacker Scam has cost Americans over $1 billion, targeting seniors through three-phase operation involving tech support,...
Family Dollar agreed to a class action lawsuit settlement to resolve claims that its Chestnut Hill coffee products were deceptively marketed as able to brew...
Everyone has cybersecurity stories involving family members. Here's a relatively common one. The conversation usually goes something like...
Discount-retail chain Family Dollar, which Dollar Tree bought in 2015 for about $9 billion, will be sold to private-equity investors for...
The University of South Florida announced the largest donation in the school's history: a $40 million gift from Arnie and Lauren Bellini.
The discount chain picked Dunnhumby to power a platform aimed at localizing product assortment to better meet shoppers' needs.
America's largest sporting goods retailer, Dick's Sporting Goods, has disclosed a cybersecurity incident involving unauthorised access to...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Family Dollar is https://www.familydollar.com.
According to Rankiteo, Family Dollar’s AI-generated cybersecurity score is 808, reflecting their Good security posture.
According to Rankiteo, Family Dollar currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Family Dollar is not certified under SOC 2 Type 1.
According to Rankiteo, Family Dollar does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Family Dollar is not listed as GDPR compliant.
According to Rankiteo, Family Dollar does not currently maintain PCI DSS compliance.
According to Rankiteo, Family Dollar is not compliant with HIPAA regulations.
According to Rankiteo,Family Dollar is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Family Dollar operates primarily in the Retail industry.
Family Dollar employs approximately 101,015 people worldwide.
Family Dollar presently has no subsidiaries across any sectors.
Family Dollar’s official LinkedIn profile has approximately 148,141 followers.
Family Dollar is classified under the NAICS code 43, which corresponds to Retail Trade.
No, Family Dollar does not have a profile on Crunchbase.
Yes, Family Dollar maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/family-dollar.
As of November 27, 2025, Rankiteo reports that Family Dollar has experienced 1 cybersecurity incidents.
Family Dollar has an estimated 15,247 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Ransomware.
Detection and Response: The company detects and responds to cybersecurity incidents through an communication strategy with public denial of involvement; clarification that data likely originated from 99 cents only stores..
Title: Dollar Tree Data Breach Claimed by INC Ransomware Group
Description: The INC Ransomware group claimed responsibility for a data breach at Dollar Tree, alleging the theft of 1.2TB of sensitive and personal data, including passport copies, payroll forms, job letters, agreements, legal correspondence, and complaints detailing sexual harassment and discrimination cases. Dollar Tree denied involvement, stating the data likely originated from 99 Cents Only Stores, from which it acquired only select real estate lease rights. The ransomware group, known for double-extortion tactics, has a history of high-profile attacks, including those on Ahold Delhaize and the UK’s NHS.
Date Publicly Disclosed: 2025-07-29
Type: Data Breach
Threat Actor: INC Ransomware (GOLD IONIC / Lynx)
Motivation: Financial GainData TheftExtortion
Common Attack Types: The most common types of attacks the company has faced is Ransomware.

Data Compromised: Passport copies, Payroll forms, Job letters, Agreements, Legal correspondence, Complaints (sexual harassment, discrimination)
Brand Reputation Impact: Potential reputational damage due to association with data breach claims
Identity Theft Risk: High (due to exposure of PII and sensitive documents)
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Personal Identifiable Information (Pii), Legal Documents, Employment Records, Sensitive Complaints and .

Entity Name: Dollar Tree
Entity Type: Retail Chain
Industry: Retail
Location: United States
Size: Fortune 500 (Revenue: $17.58B in FY2025)

Entity Name: 99 Cents Only Stores
Entity Type: Retail Chain (Defunct)
Industry: Retail
Location: United States
Customers Affected: Former employees (data allegedly sourced from this entity)

Communication Strategy: Public denial of involvement; clarification that data likely originated from 99 Cents Only Stores

Type of Data Compromised: Personal identifiable information (pii), Legal documents, Employment records, Sensitive complaints
Sensitivity of Data: High (includes passports, legal correspondence, harassment complaints)
Data Exfiltration: 1.2TB of data allegedly stolen
File Types Exposed: PDFsDocumentsScanned Images
Personally Identifiable Information: Passport copiesPayroll detailsEmployee namesLegal case details

Ransomware Strain: INC Ransomware (aka GOLD IONIC / Lynx)
Data Exfiltration: 1.2TB of data threatened for public release

Source: Hackread.com
URL: https://www.hackread.com/inc-ransomware-dollar-tree-data-breach/
Date Accessed: 2025-07-29
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Hackread.comUrl: https://www.hackread.com/inc-ransomware-dollar-tree-data-breach/Date Accessed: 2025-07-29.

Investigation Status: Ongoing; Dollar Tree denies involvement, attributes data to 99 Cents Only Stores
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Public denial of involvement; clarification that data likely originated from 99 Cents Only Stores.

Stakeholder Advisories: Public statement denying involvement and clarifying data origin
Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: was Public statement denying involvement and clarifying data origin.
Last Attacking Group: The attacking group in the last incident was an INC Ransomware (GOLD IONIC / Lynx).
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2025-07-29.
Most Significant Data Compromised: The most significant data compromised in an incident were Passport copies, Payroll forms, Job letters, Agreements, Legal correspondence, Complaints (sexual harassment, discrimination) and .
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Complaints (sexual harassment, discrimination), Passport copies, Agreements, Payroll forms, Legal correspondence and Job letters.
Most Recent Source: The most recent source of information about an incident is Hackread.com.
Most Recent URL for Additional Resources: The most recent URL for additional resources on cybersecurity best practices is https://www.hackread.com/inc-ransomware-dollar-tree-data-breach/ .
Current Status of Most Recent Investigation: The current status of the most recent investigation is Ongoing; Dollar Tree denies involvement, attributes data to 99 Cents Only Stores.
Most Recent Stakeholder Advisory: The most recent stakeholder advisory issued was Public statement denying involvement and clarifying data origin, .
.png)
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site Request Forgery (XSRF) token to an attacker-controlled domain. Angular's HttpClient has a built-in XSRF protection mechanism that works by checking if a request URL starts with a protocol (http:// or https://) to determine if it is cross-origin. If the URL starts with protocol-relative URL (//), it is incorrectly treated as a same-origin request, and the XSRF token is automatically added to the X-XSRF-TOKEN header. This issue has been patched in versions 19.2.16, 20.3.14, and 21.0.1. A workaround for this issue involves avoiding using protocol-relative URLs (URLs starting with //) in HttpClient requests. All backend communication URLs should be hardcoded as relative paths (starting with a single /) or fully qualified, trusted absolute URLs.
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2.
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the bypass of downstream OID-based security decisions. This issue has been patched in version 1.3.2.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, working with large buffers in Lua scripts can lead to a stack overflow. Users of Lua rules and output scripts may be affected when working with large buffers. This includes a rule passing a large buffer to a Lua script. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves disabling Lua rules and output scripts, or making sure limits, such as stream.depth.reassembly and HTTP response body limits (response-body-limit), are set to less than half the stack size.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can occur when the entropy keyword is used in conjunction with base64_data. This issue has been patched in version 8.0.2. A workaround involves disabling rules that use entropy in conjunction with base64_data.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.