Forever 21, Inc.
ent_019e5ab3d596b8737f612ebecf437afd
Disclosures
11
State AG · 7 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
98,930
as filed · State AG NH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Forever 21, Inc.
- Normalized
- forever 21— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300N7Q6EL65IHS133
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (11)newest first
- South Carolina State AGas victim2023-08-30
Forever 21 notified South Carolina residents of a cyber incident where an unauthorized third party accessed systems between Jan 5 and Mar 21, 2023. The breach exposed names, SSNs, DOBs, bank account numbers, and health plan data. Forever 21 engaged cybersecurity firms, notified law enforcement, and offered 12 months of Experian IdentityWorks.
- Montana State AGas victim2023-08-29
Forever 21 notified Montana residents of a cyber incident where an unauthorized third party accessed systems between Jan 5 and Mar 21, 2023. Data included names, SSNs, DOBs, bank account numbers, and health plan info. The company engaged cybersecurity firms, notified law enforcement, and offered 12 months of Experian IdentityWorks.
- Illinois State AGas victim2023-01-01
FOREVER 21 filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-608). The register records the breach as discovered on January 5, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- California State AGas victim2018-06-22
Forever 21, Inc. notified the California Attorney General that an unauthorized third party accessed two email accounts of its insurance broker, Willis Towers Watson, between February 15, 2018, and March 23, 2018. The accessed emails contained summary documents related to Forever 21 insurance claims, including names, dates of injury, injury information, and claim amounts. Medical records, SSNs, and financial information were not involved. Forever 21 launched an investigation and offered one year of credit monitoring to affected individuals.
- California State AGas victim2018-06-01
Forever 21 notified customers that an unauthorized third party accessed email accounts of its insurance broker, Willis Towers Watson, between Feb 15 and Mar 23, 2018. The emails contained claim summaries including names, dates of injury, injury details, and claim amounts. Medical records, SSNs, and financial info were not involved. Credit monitoring was offered.
- South Carolina State AGas victim2018-01-03
Forever 21, Inc. reported a payment card security incident affecting U.S. stores. Malware was installed on POS devices between April 3, 2017, and November 18, 2017, when encryption was disabled. The malware collected track data from payment cards. Encryption has been addressed, and the company is cooperating with law enforcement and payment networks.
- Oregon State AGas victim2017-12-28
Forever 21, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2017-12-28. The breach occurred during 4/3/2017 - 11/18/2017. The breach was discovered on 10/16/2017. 0 individuals were affected. Notice was sent on 11/14/201712/28/2017.
- Washington State AGas victim2017-12-28
Forever 21, Inc. notified the Washington AG of a malware incident affecting POS devices in U.S. stores between April 3 and November 18, 2017. Malware captured payment card track data (card numbers, expiration dates) when encryption was disabled. No specific count of affected individuals was provided; substitute notification was issued on Dec 28, 2017.
- California State AGas victim2017-12-28
Forever 21 reported a payment card security incident affecting U.S. stores from April 3, 2017, to November 18, 2017. Malware installed on POS devices captured payment card track data (card number, expiration date, verification code, and occasionally cardholder name) when encryption was off. The company hired security firms, addressed encryption issues, and notified payment card networks. No specific count of affected individuals was disclosed in this notice.
- New Hampshire State AGas victim2017-12-28
Forever 21, Inc. notified the New Hampshire Attorney General of a payment card security incident. Malware was installed on POS devices in U.S. stores between April 3, 2017, and November 18, 2017, when encryption was disabled. The malware exfiltrated track data (card numbers, expiration dates) and occasionally cardholder names. Forever 21 engaged security firms, contacted law enforcement, and issued public notifications.
- New Hampshire State AGas victim2008-09-16
Forever 21, Inc. notified the New Hampshire Attorney General on September 16, 2008, of a security breach involving unauthorized access to customer payment card data. The incident affected approximately 98,930 credit and debit card numbers, with transactions occurring between November 2003 and August 2007. The breach was discovered on August 5, 2008, after the U.S. Secret Service contacted the company regarding an indictment of three individuals. The compromised data included card numbers and expiration dates but excluded customer names and addresses. More than half of the affected cards were expired or inactive. Forever 21 engaged forensic consultants, worked with payment networks, and notified credit bureaus.