Data leak

BleepingComputer

πŸ“… 2023-01-05 🏒 Forever 21 HR and payroll systems
Primary Source β†—

Incident Details

Fast fashion retailer Forever 21 suffered a data breach where hackers had access to its systems from January 5 to March 21, 2023. The breach affected 539,207 current and former employees and their dependents β€” not customers. Exposed data included names, Social Security numbers, dates of birth, bank account numbers, and employee health plan information. Forever 21 disclosed the breach in August 2023 and offered 12 months of free Experian IdentityWorks credit monitoring. A previous breach at Forever 21 in 2017-2018 had compromised customer payment card data, making this a repeat incident at the retailer.

Technical Details

Initial Attack Vector
CWE-284: Improper Access Control
Vendor / Product
Forever 21 HR and payroll systems

Timeline

  1. 2023-01-05 Breach occurred
  2. 2023-08-29 Publicly disclosed
  3. 2023-08-29 Customers notified