HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
F21 OpCo LLC
bd_3fde4b2e47cb5c8b · schema v1 · pii pii-v1
Full breach record for F21 OpCo LLC →F21 OPCO, LLC d/b/a Forever 21 disclosed a cybersecurity incident occurring between January 5, 2023, and March 21, 2023. An unauthorized third party accessed systems and exfiltrated files containing names, SSNs, dates of birth, bank account numbers, and health plan information. The company engaged cybersecurity firms and law enforcement, contained the breach, and offered 12 months of credit monitoring. No evidence of fraud was found.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_8e190db9ebbc951aDelaware State AGfiled 2023-08-29Candidate
- bd_8e5ceb792c1aab49Oregon State AGfiled 2023-08-29Verified by operator
- bd_a777e26a66056638Maine State AGfiled 2023-08-29Verified by operator
- bd_b8de6d37b2a56714Washington State AGfiled 2023-08-29Verified
Show 1 more filing ↓Show fewer ↑
- bd_ddd74bf44793eb48California State AGfiled 2023-08-29Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/09/1Y-F21-Master-Individual-Notification-Letter.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 29, 2023
- Raw hash
- 324fc63b7bb32879363807a6c668cb366036f8c60aaf488fde90e19972efea07
Reporting entity
- Name
- F21 OpCo LLCnorm: f21 opco
Victim entity
- Name
- F21 OpCo LLCnorm: f21 opco
Incident
- Discovered
- Mar 20, 2023
- Materiality determined
- —
- Notification sent
- Aug 29, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 23 weeks(162 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.