Forever 21, Inc.
bd_756c891ad9759ec0 · schema v1 · pii pii-v1
Full breach record for Forever 21, Inc. →6 incidents on fileForever 21, Inc. notified the Washington AG of a malware incident affecting POS devices in U.S. stores between April 3 and November 18, 2017. Malware captured payment card track data (card numbers, expiration dates) when encryption was disabled. No specific count of affected individuals was provided; substitute notification was issued on Dec 28, 2017.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 3, 2017
Begins
Oct 1, 2017
Discovered
Dec 28, 2017
Filed
vs. sector median
+5 wks slower
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Oregon State AGbd_30d34ebfc38771b32017-12-28Candidate
- California State AGbd_84ca08f8d4d2f9432017-12-28Verified
- New Hampshire State AGbd_cc576cc5ff09fd0f2017-12-28Verified
- South Carolina State AGbd_b5afdc19050013b92018-01-03 · +6dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing Dec 28 (OR), last Jan 3 (SC) — a 6-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.