DisclosureLens
HackingRetail & ConsumerRetailStolen CredentialsData ExfiltratedCustomer Data InvolvedDelayed DiscoveryFinancial accountPIIMediumContained

Forever 21, Inc.

bd_cd685125b20a9d3e · schema v1 · pii pii-v1

Severity

Medium

Discovered

Aug 5, 2008

Filed

Sep 16, 2008

To disclose

6 weeks

Affected

98,930scope not determined

Confidence

64%
Full breach record for Forever 21, Inc.6 incidents on file

Forever 21, Inc. notified the New Hampshire Attorney General on September 16, 2008, of a security breach involving unauthorized access to customer payment card data. The incident affected approximately 98,930 credit and debit card numbers, with transactions occurring between November 2003 and August 2007. The breach was discovered on August 5, 2008, after the U.S. Secret Service contacted the company regarding an indictment of three individuals. The compromised data included card numbers and expiration dates but excluded customer names and addresses. More than half of the affected cards were expired or inactive. Forever 21 engaged forensic consultants, worked with payment networks, and notified credit bureaus.

Incident timeline

undetected · 1714 days
discovery → filing · 6 weeks / 42 days

Nov 26, 2003

Begins

Aug 5, 2008

Discovered

Sep 16, 2008

Filed

vs. sector median

2 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed98,930 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.