HackingData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
F21 OpCo LLC
bd_ddd74bf44793eb48 · schema v1 · pii pii-v1
Full breach record for F21 OpCo LLC →Forever 21 (F21 OpCo LLC) disclosed a cyber incident where an unauthorized third party accessed systems between Jan 5 and Mar 21, 2023. The breach was discovered on Mar 20, 2023. Affected data includes names, SSNs, DOBs, bank account numbers, and health plan information. The company engaged forensic firms, notified law enforcement, and contained the access. No evidence of misuse was found. Complimentary identity monitoring was offered.
California clockDiscovered Mar 20, 2023 → Notified Aug 29, 2023162d ✗ CA 60-day late23 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_3fde4b2e47cb5c8bDelaware State AGfiled 2023-08-29Verified
- bd_8e190db9ebbc951aDelaware State AGfiled 2023-08-29Candidate
- bd_8e5ceb792c1aab49Oregon State AGfiled 2023-08-29Verified by operator
- bd_a777e26a66056638Maine State AGfiled 2023-08-29Verified by operator
Show 1 more filing ↓Show fewer ↑
- bd_b8de6d37b2a56714Washington State AGfiled 2023-08-29Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-572568
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 29, 2023
- Raw hash
- 0c3d20e6a8de3ae31b192f1b820ecbfa05249ff29fd0b897476e20ccebafd079
Reporting entity
- Name
- F21 OpCo LLCnorm: f21 opco
Victim entity
- Name
- F21 OpCo LLCnorm: f21 opco
Incident
- Discovered
- Mar 20, 2023
- Materiality determined
- —
- Notification sent
- Aug 29, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 23 weeks(162 days from discovery to filing)
- Compliance flags
- CA 60-day late · 162d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 20, 2023→ Notified: Aug 29, 2023162d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.