Data leak
BleepingComputer
Primary Source βIncident Details
Fast fashion retailer Forever 21 suffered a data breach where hackers had access to its systems from January 5 to March 21, 2023. The breach affected 539,207 current and former employees and their dependents β not customers. Exposed data included names, Social Security numbers, dates of birth, bank account numbers, and employee health plan information. Forever 21 disclosed the breach in August 2023 and offered 12 months of free Experian IdentityWorks credit monitoring. A previous breach at Forever 21 in 2017-2018 had compromised customer payment card data, making this a repeat incident at the retailer.
Technical Details
- Initial Attack Vector
- CWE-284: Improper Access Control
- Vendor / Product
- Forever 21 HR and payroll systems
Timeline
- 2023-01-05 Breach occurred
- 2023-08-29 Publicly disclosed
- 2023-08-29 Customers notified