J.Crew Group, Inc. notified customers of a credential-based account compromise affecting jcrew.com accounts. Stolen email/password credentials were used by an unauthorized party to log into customer accounts in or around April 2019. Accessible data included last four digits of stored credit card numbers, expiration dates, card types, billing addresses, and order/shipping information. Accounts were disabled and password resets required.