Forever 21, Inc.
bd_cd685125b20a9d3e · schema v1 · pii pii-v1
Full breach record for Forever 21, Inc. →Forever 21, Inc. notified the New Hampshire Attorney General on September 16, 2008, of a security breach involving unauthorized access to customer payment card data. The incident affected approximately 98,930 credit and debit card numbers, with transactions occurring between November 2003 and August 2007. The breach was discovered on August 5, 2008, after the U.S. Secret Service contacted the company regarding an indictment of three individuals. The compromised data included card numbers and expiration dates but excluded customer names and addresses. More than half of the affected cards were expired or inactive. Forever 21 engaged forensic consultants, worked with payment networks, and notified credit bureaus.
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/forever-21-20080916.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 16, 2008
- Raw hash
- 10bad53d1bac73c0a18f2fb76ea3c88548591d85da4dc99de979a3679426405d
Reporting entity
- Name
- Forever 21, Inc.norm: forever 21
Victim entity
- Name
- Forever 21, Inc.norm: forever 21
Incident
- Discovered
- Aug 5, 2008
- Materiality determined
- —
- Notification sent
- Sep 16, 2008
- Affected individuals
- 98,930
- Data types
- FINANCIAL_ACCOUNTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Contacted by the U.S. Secret Service and was advised that our company was identified in the indictment
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 6 weeks(42 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.