Forever 21, Inc.
bd_cd685125b20a9d3e · schema v1 · pii pii-v1
Full breach record for Forever 21, Inc. →6 incidents on fileForever 21, Inc. notified the New Hampshire Attorney General on September 16, 2008, of a security breach involving unauthorized access to customer payment card data. The incident affected approximately 98,930 credit and debit card numbers, with transactions occurring between November 2003 and August 2007. The breach was discovered on August 5, 2008, after the U.S. Secret Service contacted the company regarding an indictment of three individuals. The compromised data included card numbers and expiration dates but excluded customer names and addresses. More than half of the affected cards were expired or inactive. Forever 21 engaged forensic consultants, worked with payment networks, and notified credit bureaus.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 26, 2003
Begins
Aug 5, 2008
Discovered
Sep 16, 2008
Filed
vs. sector median
2 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.