HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
F21 OPCP LLC
bd_50289e0c2dbaee12 · schema v1 · pii pii-v1
Full breach record for F21 OPCP LLC →F21 OPCP LLC (operating as Forever 21) disclosed a cybersecurity incident affecting systems between January 5, 2023, and March 21, 2023. An unauthorized third party accessed systems and exfiltrated files containing names, Social Security numbers, dates of birth, bank account numbers, and health plan information. The company engaged cybersecurity firms and law enforcement, contained the breach, and offered 12 months of Experian IdentityWorks. No evidence of fraud was found.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://cca.hawaii.gov/wp-content/uploads/2026/05/Letter.2023-0949.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 29, 2023
- Raw hash
- 9dbf5ce5d02d2381bcc47925da2be93ff39df0083698e4d1241e0386f949d404
Reporting entity
- Name
- F21 OPCP LLCnorm: f21 opcp
Victim entity
- Name
- F21 OPCP LLCnorm: f21 opcp
Incident
- Discovered
- Mar 20, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 23 weeks(162 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.