RetailInvestigation Open

Petco Animal Supplies Stores, Inc. (“Petco”) Data Breach

Petco Animal Supplies Stores, Inc. (“Petco”) was the subject of a data breach notification filed with the CA Attorney General. The AG filing was recorded on December 3, 2025. The breach or discovery date reported in the filing is July 7, 2025.

CA
State Filed
Dec 3, 2025
AG Filing Date
Unknown
Records Affected

Data Exposed

Full NameEmail AddressMailing AddressPhone NumberPassword or Credential HashPurchase and Order History+1 more

Tell Us About Your Notice Letter

Received a data breach notification letter? Fill out the form — an attorney will review your mailing and contact you. No cost, no obligation.

Start typing to find a matching case, or enter a company not yet listed.

Attach a copy of your data breach notification letter. Accepted: PDF, JPG, PNG — max 10 MB.

No attorney-client relationship is created by submitting this form. Attorney Advertising.

The Breach — What We Know

Petco Animal Supplies Stores, Inc. (“Petco”) was the subject of a data breach notification filed with the CA Attorney General. The AG filing was recorded on December 3, 2025. The breach or discovery date reported in the filing is July 7, 2025.

Petco Animal Supplies Stores, Inc. (“Petco”) is one of the nation's premier omnichannel pet specialty retailers, offering comprehensive pet supplies, foods, grooming services, and veterinary care through hundreds of brick-and-mortar storefronts and expansive e-commerce platforms. Because millions of consumers routinely utilize Petco's digital channels, mobile applications, and loyalty programs to manage recurring pet care purchases, grooming appointments, and veterinary subscriptions, the company routinely collects and centralizes vast volumes of sensitive consumer data. This includes not only basic customer profiles, billing addresses, and contact details, but also encrypted payment card tokens, purchase histories, and occasionally veterinary health records associated with pets and their owners. In 2025, Petco reported a significant data security incident to the California Attorney General, highlighting vulnerabilities within its corporate IT network or third-party digital vendor infrastructure. In the retail sector, breaches of this magnitude frequently stem from sophisticated cyber threats such as credential stuffing attacks, unauthorized intrusions into e-commerce databases, or compromises of third-party software vendors embedded within the retail checkout and customer relationship management (CRM) ecosystem. Such incidents often go undetected for weeks or months, allowing malicious actors to quietly siphon off consumer databases containing millions of customer records before security teams identify abnormal network traffic or system anomalies. The exposure of retail consumer records carries severe, cascading risks for affected individuals. When databases encompassing full names, email addresses, mailing addresses, purchase histories, and payment card information are compromised, cybercriminals immediately weaponize this data to execute targeted phishing campaigns, credential-stuffing attacks against other online services, and fraudulent financial transactions. Because retail customers frequently reuse passwords across multiple websites, an exposure at a major retailer like Petco can easily lead to broader account takeovers across banking, email, and utility platforms. Furthermore, detailed purchase history and billing data allow bad actors to craft hyper-realistic social engineering scams tailored to the victim's consumer habits. As a major commercial entity operating within California, Petco Animal Supplies Stores, Inc. (“Petco”) is bound by strict statutory mandates under state consumer protection statutes, including the California Consumer Privacy Act (CCPA) and California's Unfair Competition Law, alongside the overarching enforcement authority of the Federal Trade Commission Act. These legal frameworks require corporations to implement and maintain reasonable, industry-standard security procedures and practices appropriate to the nature of the personal information collected. The occurrence of a widespread data breach strongly indicates a potential failure of these administrative, technical, and physical safeguards—such as outdated encryption protocols, inadequate network segmentation, or insufficient vendor risk management—leaving consumer data vulnerable to unauthorized exfiltration. Receiving a formal data breach notification letter from Petco Animal Supplies Stores, Inc. (“Petco”) is a clear legal admission that your confidential information was compromised due to inadequate corporate cybersecurity practices. Under modern consumer privacy jurisprudence, the receipt of such a notice establishes legal standing to initiate or participate in a class action lawsuit aimed at holding the company accountable. Class members do not need to prove that direct financial theft has already occurred to seek legal redress; the imminent and credible risk of future identity theft and the loss of privacy are sufficient grounds for action. Our law firm is actively investigating this breach on a contingency fee basis, meaning affected consumers pay zero upfront costs or out-of-pocket expenses, and we only collect attorney fees if a successful recovery is secured on your behalf.

What's at Risk for You

Based on the data types reported, affected individuals face:

SIM Swap & Vishingmedium risk

Phone numbers exposed in breaches are used for SIM swapping attacks — hijacking your number to bypass two-factor authentication on financial accounts.

Do You Qualify for Compensation?

  • ✓You received a written data breach notification letter from Petco Animal Supplies Stores, Inc. (“Petco”)
  • ✓You are or were a customer, patient, or employee of Petco Animal Supplies Stores, Inc. (“Petco”)
  • ✓Your information was held by Petco Animal Supplies Stores, Inc. (“Petco”) in CA

Your Legal Rights

What the California Consumer Privacy Act (CCPA) and federal statutes entitle you to recover:

Lost Time & Remediation Costs

The hours spent responding to a data breach — canceling accounts, contacting credit bureaus, updating passwords, and investigating fraud — represent compensable economic harm in data breach litigation.

Account Compromise Damages

When login credentials are exposed, the costs of downstream account compromises — password managers, security audits, and recovery costs for hijacked downstream accounts — can be recovered. Courts in recent class actions have awarded damages for credential exposure even without proven misuse.

Emotional Distress

Data breach victims regularly report anxiety, loss of sleep, and ongoing fear of identity theft. These non-economic harms are cognizable injuries in data breach litigation, particularly in cases involving SSN or medical record exposure.

Note: an attorney general breach filing does not by itself establish a settlement fund, a payment amount, or a claim deadline. If an official settlement notice is later issued, rely on that notice for payment details and deadlines.

Frequently Asked Questions

Do I need proof that my data was misused to file a claim against Petco Animal Supplies Stores, Inc. (“Petco”)?

No. Under California Consumer Privacy Act (CCPA) and federal law, the unauthorized exposure of your personal data — regardless of whether it has been actively misused — can be sufficient grounds for a claim. The breach itself is the injury.

How much does filing a claim cost?

Nothing. The Law Office of David S. Harris handles data breach cases on contingency — you pay zero upfront and owe nothing unless compensation is recovered.

Is it too late to file a claim?

Statutes of limitations for data breach claims vary by state but typically run 2–4 years. Depending on when you learned of the breach, you may still have time. Contact our office for a free eligibility review — there is no cost to find out.

What if Petco Animal Supplies Stores, Inc. (“Petco”) offered me free credit monitoring after the breach?

Accepting free credit monitoring from Petco Animal Supplies Stores, Inc. (“Petco”) does not waive your right to pursue legal action unless you signed a specific release waiving claims. In most cases, victims who accepted monitoring can still file.

Do I need to have received a notice letter to be eligible?

Not necessarily. Many data breach victims are never notified directly. If your personal information was held by Petco Animal Supplies Stores, Inc. (“Petco”) during the relevant period, you may still qualify even without receiving a letter. A free eligibility review can confirm your status.

How long does a data breach class action lawsuit take?

Most data breach class actions resolve within 18 to 36 months, though timelines vary by court and complexity. Your participation requires minimal effort — typically completing a claim form. Our office handles all litigation; you are notified when a settlement is reached.

Received a notification letter from Petco Animal Supplies Stores, Inc. (“Petco”)?

What it means and what to do next.

Letter Guide →

Petco Animal Supplies Stores, Inc. (“Petco”) breach?

Free case review · No fee unless you win

Call Now