Article Details

Original Article Text

Click to Toggle View

Forever 21 data breach: hackers accessed info of 500,000. Forever 21 clothing and accessories retailer is sending data breach notifications to more than half a million individuals who had their personal information exposed to network intruders. The company is operating 540 outlets worldwide and employs roughly 43,000 people. A sample of the data breach notice shared with the Office of the Maine Attorney General says that the company detected a cyberattack on several of its systems on March 20. The investigation revealed that hackers had intermittent access to Forever 21 systems between January and March this year and leveraged this access to steal data. “The investigation revealed that an unauthorized third party accessed certain Forever 21 systems at various times between January 5, 2023, and March 21, 2023,” reads the notice. “Findings from the investigation indicate the unauthorized third party obtained select files from certain Forever 21 systems during this time period” - Forever 21 The data breach notice sent on August 29 to 539,207 impacted individuals mentions the following data types as potentially exposed: BleepingComputer has contacted Forever 21 to determine if the security incident has impacted both customers and employees, and a spokesperson of the firm has sent the following statement: The event was limited to current and former Forever 21 employees and did NOT affect personal data pertaining to Forever 21 customers. In the notice, Forever 21 reports that they have taken measures to ensure the hackers have erased the stolen data, an indication that the company communicated with the attacker. This typically happens after ransomware attacks, when the victim engages in negotiation with the hackers to pay a more reasonable ransom. However, a ransomware attack on Forever 21 has not been confirmed. Also, the firm states it has no indication that the stolen data has been shared with other cybercriminals and characterizes the risk arising from the event for exposed people as “low.” Additionally, all notice recipients will find enclosed instructions on how to enroll for a free-of-charge 12-month fraud and identity theft protection service. In November 2017, Forever 21 notified its customers of another data breach impacting its payments system, resulting in the compromise of card data from transactions made between March and October 2017. Update 9/1: Post updated to add Forever 21 clarification on the scope of the impact

Daily Brief Summary

DATA BREACH // Forever 21 Data Breach Exposes Personal Information of 500,000 Individuals

Forever 21, a clothing and accessories retailer, suffered a data breach that exposed the personal information of over 500,000 individuals

Hackers had intermittent access to Forever 21 systems between January and March, and stole select files during this time

The breach primarily affected current and former Forever 21 employees, not customers

Forever 21 has taken steps to ensure the stolen data has been erased, indicating potential communication with the attackers

There is no confirmation of a ransomware attack, and the company believes the risk to exposed individuals is low

Impacted individuals will receive instructions on enrolling in a free 12-month fraud and identity theft protection service

This is not the first data breach for Forever 21, as they previously notified customers of a breach in 2017 affecting payment card data from transactions made between March and October