MalwareRansomwareData ExfiltratedTargetedPCIFINANCIAL_ACCOUNTLowContained
Forever 21, Inc.
bd_84ca08f8d4d2f943 · schema v1 · pii pii-v1
Full breach record for Forever 21, Inc. →Forever 21, Inc. issued a supplemental notice regarding a payment card security incident at U.S. retail stores. Malware was installed on POS devices and log devices between April 3, 2017, and November 18, 2017, capturing payment card track data when encryption was disabled. The incident involved unauthorized network access and data exfiltration. No specific count of affected individuals was disclosed.
California clockDiscovered Oct 15, 2017 → Notified Dec 28, 201774d ✗ CA 60-day late11 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_30d34ebfc38771b3Oregon State AGfiled 2017-12-28Candidate
- bd_756c891ad9759ec0Washington State AGfiled 2017-12-28Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-131937
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 28, 2017
- Raw hash
- 41e1cbdec3c8bf429474c57217e91a161d94545ac6388adb2e100f42e571c772
Reporting entity
- Name
- Forever 21, Inc.norm: forever 21
- Domain
- forever21.com
Victim entity
- Name
- Forever 21, Inc.norm: forever 21
- Domain
- forever21.com
Incident
- Discovered
- Oct 15, 2017
- Materiality determined
- Dec 28, 2017
- Notification sent
- Dec 28, 2017
- Affected individuals
- Not disclosed
- Data types
- PCIFINANCIAL_ACCOUNT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Supporting law enforcement’s investigation of this incident
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(74 days from discovery to filing)
- Compliance flags
- CA 60-day late · 74d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 15, 2017→ Notified: Dec 28, 201774d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.