HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICHEALTH_BASICLowContained
Forever 21, Inc.
bd_a57497f757eef0ba · schema v1 · pii pii-v1
Full breach record for Forever 21, Inc. →Forever 21 notified customers that an unauthorized third party accessed email accounts of its insurance broker, Willis Towers Watson, between Feb 15 and Mar 23, 2018. The emails contained claim summaries including names, dates of injury, injury details, and claim amounts. Medical records, SSNs, and financial info were not involved. Credit monitoring was offered.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_7af49a6672ae4063California State AGfiled 2018-06-22(21d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-136761
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 1, 2018
- Raw hash
- cd494e73baa34a8980a391cc3f52b5c4f07b7a82b41b75839ba848f4bcac3a2e
Reporting entity
- Name
- Forever 21, Inc.norm: forever 21
Victim entity
- Name
- Forever 21, Inc.norm: forever 21
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Third party
- via Willis Towers Watson
- Initial access
- trusted_relationship
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.