Forever 21, Inc.
ent_019e5ab3d596b8737f612ebecf437afd
Disclosures
7
State AG · 5 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
98,930
as filed · State AG NH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Forever 21, Inc.
- Normalized
- forever 21— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300N7Q6EL65IHS133
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- 🦬Montana State AGas victim2023-08-29
Forever 21 reported a data breach to the Montana Attorney General. The breach was reported on 2023-08-29. The breach occurred from 1/5/2023 to 3/21/2023. 15 Montana residents were affected.
- 🐻California State AGas victim2018-06-22
Forever 21, Inc. notified California AG that an unauthorized third party accessed two employees' email accounts at third-party broker Willis Towers Watson between Feb 15 and Mar 23, 2018. The accounts contained summary documents with claimant names, injury details, and claim amounts. No medical records, SSNs, or financial info were exposed. Credit monitoring offered.
- 🐻California State AGas victim2018-06-01
Forever 21 notified customers that an unauthorized third party accessed email accounts of its insurance broker, Willis Towers Watson, between Feb 15 and Mar 23, 2018. The emails contained claim summaries including names, dates of injury, injury details, and claim amounts. Medical records, SSNs, and financial info were not involved. Credit monitoring was offered.
- 🦫Oregon State AGas victim2017-12-28
Forever 21, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2017-12-28. The breach occurred during 4/3/2017 - 11/18/2017. The breach was discovered on 10/16/2017. 0 individuals were affected. Notice was sent on 11/14/201712/28/2017.
- 🌲Washington State AGas victim2017-12-28
Forever 21, Inc., a business sector entity reported a malware incident to the Washington Attorney General. The organization became aware of the incident on 2017-10-01 and filed notice on 2017-12-28. 88 days elapsed between awareness and notification. 181 days to identify the breach. 48 days to contain the breach.
- 🐻California State AGas victim2017-12-28
Forever 21, Inc. issued a supplemental notice regarding a payment card security incident at U.S. retail stores. Malware was installed on POS devices and log devices between April 3, 2017, and November 18, 2017, capturing payment card track data when encryption was disabled. The incident involved unauthorized network access and data exfiltration. No specific count of affected individuals was disclosed.
- ⛰️New Hampshire State AGas victim2008-09-16
Forever 21, Inc. notified the New Hampshire Attorney General on September 16, 2008, of a security breach involving unauthorized access to customer payment card data. The incident affected approximately 98,930 credit and debit card numbers, with transactions occurring between November 2003 and August 2007. The breach was discovered on August 5, 2008, after the U.S. Secret Service contacted the company regarding an indictment of three individuals. The compromised data included card numbers and expiration dates but excluded customer names and addresses. More than half of the affected cards were expired or inactive. Forever 21 engaged forensic consultants, worked with payment networks, and notified credit bureaus.