← Blog

Walmart Data Breaches: Full Timeline Through 2026

Share on X

People search Walmart data breach timeline because millions of customers entrust payment and identity data to everyday transactions. BreachHistory indexes 9 Walmart-linked incidents, with headline counts up to 1.3M+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.

Why Walmart breach history matters

Walmart operates in Retail (United States). Across indexed rows, recurring themes include cloud and database misconfiguration, third-party and supply-chain exposure, zero-day exploitation and malware. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.

Full timeline through 2026

2023 — full timeline

Cataloged incident. Walmart has experienced multiple data breach and security incidents over the years. Full timeline through 2023. Exposed categories include Details not publicly disclosed. No attested victim count is published for this row yet. See the wlmx and canonical BreachHistory entry.

2021 — Walmart Canada website order lookup flaw exposes customer data

Cataloged incident. Security flaw on Walmart Canada order lookup exposed names, addresses, order dates/contents, payment methods, last four digits of cards. Customer reported; media replicated. Redirects added; unclear if data was collected by attackers. Exposed categories include Names, Addresses, Payment information. No attested victim count is published for this row yet. See the twm2101 and canonical BreachHistory entry.

2019 — Vendor (Compucom) employees snoop internal Walmart emails

Cataloged incident. Compucom employees investigated for accessing internal Walmart emails without authorization (late 2015–early 2016) to gain edge on contract bids. Discovered when photo of internal message was mistakenly forwarded. Exposed categories include Email addresses, Employee data, Messages, Internal documents. No attested victim count is published for this row yet. See the twm1903 and canonical BreachHistory entry.

2018 — — Walmart: Location of breached information: Unauthorized…

Cataloged incident. Location of breached information: Unauthorized Access/Disclosure Business associate present: No Exposed categories include Personal information. BreachHistory cites approximately 741 affected records in this row. See the walmart2018 and canonical BreachHistory entry.

2018 — MBM (Limoges Jewelry) exposes 1.3M customers — S3 bucket

Cataloged incident. MBM Company left Amazon S3 bucket public; 1.3M Walmart (and other retailers) customer records exposed—names, addresses, phones, emails, plaintext passwords. Records from 2000 to early 2018. Exposed categories include Email addresses, Passwords, Passwords (plain text), Names, Addresses, Phone numbers. BreachHistory cites approximately 1.3M+ affected records in this row. See the twm1803 and canonical BreachHistory entry.

2016 — — Walmart: As reported by Health and Human Services…

Cataloged incident. As reported by Health and Human Services unauthorized access/disclosure electronic medical record. No specific information as to what information was compromised as provided by health and human services.More Information: https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf Exposed categories include Personal information. BreachHistory cites approximately 5K+ affected records in this row. See the walmart2016 and canonical BreachHistory entry.

2015 — Walmart Canada/CVS — PNI Digital Media photo vendor breach

Cataloged incident. Canadian third-party PNI Digital Media (Staples) photo processing breach potentially exposed credit card info of millions. Retailers disabled photo processing on sites and apps. Exposed categories include Credit card numbers, Credit/financial data. No attested victim count is published for this row yet. See the twm1507 and canonical BreachHistory entry.

2015 — — Walmart: Hacking, 1,300,000 records

Cataloged incident. Data breach reported. retail organization. Method: hacked. Source: Wikipedia List of data breaches. Exposed categories include Personal and demographic data. BreachHistory cites approximately 1.3M+ affected records in this row. See the walmart2015-1300000-wiki2 and canonical BreachHistory entry.

2009 — POS source code stolen (2005–2006), sent to Belarus

Cataloged incident. Hackers targeted POS development team; source code and sensitive data sent to Belarus. Discovered 2006 via server crash (password-cracking tool). VPN accounts of former employee not closed. 800+ machines potentially targeted. Exposed categories include Passwords, Source code, Employee data. No attested victim count is published for this row yet. See the twm0910 and canonical BreachHistory entry.

Patterns and analysis

  • Cloud and database misconfiguration — appears across multiple Walmart catalog entries; prioritize controls that address this class of failure.
  • Third-party and supply-chain exposure — appears across multiple Walmart catalog entries; prioritize controls that address this class of failure.
  • Zero-day exploitation and malware — appears across multiple Walmart catalog entries; prioritize controls that address this class of failure.
  • Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
  • 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.

What to do if you may be affected

  1. Step 1: Enable phishing-resistant MFA on every account tied to this brand.
  2. Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
  3. Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
  4. Step 4: Use virtual card numbers for online checkout where your bank supports it.
  5. Step 5: Bookmark the Walmart company page for new 2026+ disclosures.

Canonical BreachHistory hub

Explore every indexed row: breachhistory.com/walmart · Latest: wlmx.

Sources: BreachHistory catalog (9 rows for Walmart), company and regulator disclosures cited in individual breach records.