Attorney Advertising · Informational Only · Not Legal Advice · Editorial Policy

Forever 21 Data Breach Class Action Claims Customer Payment Data Was Exposed

The Forever 21 data breach that triggered a class action lawsuit did not actually expose customer payment data—a distinction critical to understanding your exposure. The 2023 breach, discovered in March and publicly disclosed in August of that year, compromised sensitive personal information from 539,207 individuals, but primarily affected Forever 21 employees and former employees, not shoppers. The exposure included Social Security numbers, dates of birth, and bank account information (without PINs), making this a particularly serious identity theft risk despite not being a payment card compromise.

The lawsuit, formally titled class action case 2:23-cv-08651 in the U.S. District Court for the Central District of California, was filed on September 7, 2023, by law firm Shub & Johns LLC. The case consolidated with other similar actions and had lead counsel officially appointed in June 2024. The distinction between employee data exposure and customer payment data matters because it affects who can claim damages and what compensation might be available—and it’s important to note that a separate, earlier Forever 21 breach from 2017 did expose customer payment card data and was already settled with compensation approved in April 2022.

Table of Contents

What Data Did the Forever 21 Breach Actually Expose?

The 2023 Forever 21 breach exposed a combination of deeply sensitive personal and financial information that extends beyond typical payment card data. The compromised records included full names, Social Security numbers, and dates of birth—three pieces of information that together form the core ingredients for identity theft. Additionally, bank account numbers were exposed during the breach window of January 5, 2023 through March 21, 2023, though critically, the PIN codes and access credentials were not compromised, which provided at least partial protection against immediate unauthorized withdrawals.

A secondary data exposure involved Forever 21 employee health plan information, which could expose individuals to targeted phishing, fraud, or medical identity theft. The difference between this breach and the 2017 Forever 21 payment card breach is significant: while the earlier breach compromised credit card numbers and expiration dates from customers, the 2023 breach primarily affected employment records. If you were a Forever 21 customer but not an employee or former employee during the breach period, you were likely not affected by the 2023 incident, though you may have been impacted by the 2017 breach instead.

The Timeline: From Breach Discovery to Public Notification

Forever 21 discovered the breach on March 20, 2023, but did not publicly announce it until August 29, 2023—a five-month delay that raised concerns among cybersecurity experts and regulators about the speed of notification. Under most state breach notification laws, companies are required to notify affected individuals without unreasonable delay, though definitions of “unreasonable” vary. A five-month gap between discovery and notification is commonly scrutinized as potentially violating duty-of-care standards, and this timeline is one reason the class action alleges negligence in addition to the breach itself.

The actual breach period itself lasted from January 5 to March 21, 2023—more than 2.5 months during which attackers had access to Forever 21’s employee databases. This extended exposure window means affected individuals had their sensitive information at risk for an extended period before either Forever 21 or the affected employees knew about it. The notification delay compounded the problem, as individuals had no opportunity to monitor their accounts, place fraud alerts, or take protective action during the months between actual exposure and awareness.

Forever 21 Data Breaches by Year and Impact Type2017 Payment Breach150000 Individuals affected (estimated for 2017)2023 Employee Breach539207 Individuals affected (estimated for 2017)Source: Breach notification filings; Shub & Johns LLP; Bloomberg Law

Class Action Case Status and What It Means

The lawsuit was consolidated on February 27, 2024, bringing together multiple class actions filed by different plaintiffs into a single case overseen by Judge Samantha Holbrook of Shub & Johns LLP, who was appointed as lead counsel in June 2024. As of mid-2024, the litigation was still active with no settlement reached, which means the case is in early-to-mid stages where both sides are conducting discovery (exchanging evidence and information). Settlement discussions typically occur later in the litigation process, after both parties have a clearer picture of the evidence and potential liability.

The class action lawsuit names Forever 21 as the defendant and alleges that the company failed to implement adequate cybersecurity measures to protect employee personal information and failed to notify affected individuals promptly upon discovering the breach. The case is being pursued in federal court in California, where Forever 21 is headquartered, under case number 2:23-cv-08651. Class action cases of this type typically result in settlements ranging from modest per-person payments to more substantial compensation, depending on the severity of the breach, the company’s resources, and the strength of the evidence—but outcomes can vary dramatically based on these factors.

Who Is Eligible and How to Protect Yourself

Eligibility for the class action is limited to individuals whose personal information was exposed in the 2023 breach—primarily Forever 21 employees and former employees who worked for the company between January and March 2023. If you received a breach notification letter from Forever 21 in August 2023 or later, you were likely part of the affected population. The notification letters included information about free credit monitoring services, which is the first protective step recommended by law enforcement and cybersecurity agencies.

You should take several immediate steps regardless of whether you pursue the class action claim: place a fraud alert with the three major credit bureaus (Equifax, Experian, and TransUnion), consider freezing your credit to prevent unauthorized accounts from being opened in your name, and monitor your bank accounts and credit reports regularly for unauthorized activity. The compromise of your Social Security number is particularly serious because it can be used to file fraudulent tax returns, open loans, or commit other identity fraud that may not surface immediately. Identity theft protection can take years to fully resolve in severe cases, making proactive monitoring essential.

Comparing the 2023 Employee Breach to Forever 21’s 2017 Customer Payment Breach

Forever 21 experienced a previous major data breach in 2017 that affected a different group of victims in a different way. The 2017 breach exposed payment card data (card numbers, expiration dates, and cardholder names) from customers who had made purchases on the company’s website between April 13 and October 24, 2017. That breach was settled through the case Hameed-Bolden v.

Forever 21, with the settlement approved by the court on April 21, 2022—five years after the breach occurred. The 2017 settlement offer affected customers up to $250 in expense reimbursement, free credit monitoring and identity theft protection services, and up to $10,000 in reimbursement for extraordinary expenses directly caused by the breach (such as legal fees or documented fraud losses). The 2023 employee breach is a separate case with different affected parties, though some individuals may have been impacted by both breaches if they were both customers and employees. The existence of two separate Forever 21 breaches six years apart suggests a pattern of inadequate cybersecurity practices, which strengthens the legal argument in the current 2023 case.

What the Breach Notification Letters Should Have Told You

If you received a breach notification letter from Forever 21 in August or September 2023, the letter should have clearly stated that your Social Security number, date of birth, and bank account number were exposed. The letter should also have included information about the free credit monitoring and identity theft protection services that Forever 21 was offering as part of their response to the breach. Many companies offer 12 to 24 months of free monitoring, though the terms vary.

The notification letter should have included contact information for the law firms handling the class action, or at minimum, information about how to learn more about your rights. Some individuals reported receiving minimal information about the breach, which is why independent research and consulting with a consumer protection attorney can be valuable. The quality and timeliness of breach notification letters is sometimes itself a point of litigation, as companies have a legal duty to provide clear, comprehensive, and prompt information.

Bank Account Exposure and Identity Theft Risks

The exposure of bank account numbers without PIN codes represents a significant but not absolute security risk. While criminals cannot immediately drain accounts without the access codes, the account numbers can be used for fraudulent ACH (Automated Clearing House) transfers, setting up unauthorized bill payments, or conducting account takeover attacks through social engineering. Bank account numbers are harder to compromise than credit card numbers because they don’t have embedded security features like CVV codes, but they’re also harder to cancel and replace.

If your bank account number was exposed in the Forever 21 breach, you should monitor your bank statements and account activity closely for unauthorized transactions. Contact your bank directly and ask if they can generate a new account number, though some financial institutions may be reluctant to do this unless there is documented fraudulent activity. Many banks offer free fraud monitoring and zero-fraud guarantees for legitimate customer losses, which provides some protection, but prevention through close monitoring remains the most effective approach during the post-breach period.


You Might Also Like

Caring for someone with dementia? Find practical guides at HelpDementia.com. Working out a skin routine? Evidence-based answers at AcneAdvocate.com. Forgot the name of a movie? Identify it at FindThisMovie.com. Was your data exposed? Track active breaches at DataBreachRadar.com.

We use cookies to run this site, measure how it’s used, and show ads. Choose “Essentials only” to limit cookies to what the site needs to work. Privacy Policy.