U.S. pet products and services retailer Petco has disclosed a customer data exposure that made highly sensitive personal information accessible online due to a misconfigured software setting.
The company has notified regulators in multiple U.S. states, including Texas, California, Massachusetts and Montana, and begun informing affected individuals. Letters to customers filed with the states’ attorneys general confirmed that an unauthorized party could access their personally identifiable information.
Regulatory Notices Reveal Exposure of High-Risk Personal Data
Petco has not said how many customers were affected in total, although California state law requires companies to disclose breaches affecting more than 500 customers. The retailer serves around 24 million customers.
The sensitivity of the data involved, which includes customers’ social security numbers (SSNs), driver’s license numbers, dates of birth and financial account information, has made the incident significant regardless of the scale.
That information provides the identifiers most frequently used by fraudsters in identity theft, account takeover, tax fraud and other crimes. Even a small number of victims is enough to generate lasting financial and emotional fallout.
SSNs and bank account details are not as easily reissued as a password reset, and security risks can persist for years. That causes prolonged anxiety for customers and requires brands to invest in extended repair work in rebuilding relationships.
An Internal System Error With Customer Experience Implications
Petco attributed the incident to an internal software configuration error. In the notice filed with California’s attorney general, the company wrote that it discovered “a setting within one of our software applications that inadvertently allowed certain files to be accessible online.”
“We discovered the issue on our own through a routine security review. After discovering the issue, we immediately took steps to correct the issue and to remove the files from further online access.”
The company added that it has implemented “additional security measures and technical controls to enhance the security of our applications.”




