Publish date
August 10, 2026
{x} minute read
Written by
Reviewed by
Table of contents

Retail is the most consistently targeted consumer-facing sector in the history of breach reporting, and the reason is structural. Retailers concentrate payment card data, run point-of-sale (POS) estates across thousands of stores, load high-traffic checkouts with third-party JavaScript, and depend on a deep bench of suppliers, IT outsourcers, and cloud platforms. As of August 2026, the largest and most consequential retail data breaches span three eras: the POS malware era of Target, TJX, and Home Depot; the client-side skimming and credential era of Magecart, British Airways, and the 2024 Snowflake campaign; and the identity and social engineering era defined by the 2025 Scattered Spider attacks on Marks and Spencer, Co-op, and Harrods.

The list below ranks incidents primarily by records affected, while keeping high-notability breaches that mattered more for their legal aftermath than their raw counts. Figures that are disputed, estimated, attacker-claimed, or sourced from Have I Been Pwned rather than the breached company are flagged inline, and scraping incidents are distinguished from genuine database exfiltration so you can tell a headline number from a verified one.

Compliance landscape and sector statistics

Every incident below sits on top of the same regulatory and cost baseline, and that baseline shifted hard in 2024 and 2025. Payment security rules now reach into the customer's browser, privacy regulators on three continents have started fining retailers at scale, and the sector's breach economics run against the wider market. Understanding this context is what separates reading a breach list from acting on it.

PCI DSS 4.0.1 and the new e-commerce requirements

The Payment Card Industry Data Security Standard (PCI DSS) v4.0, published in March 2022, was the largest rewrite of the standard since its first release. It introduced a customized approach that lets an entity meet a security objective through its own validated controls, expanded multi-factor authentication to all access into the cardholder data environment, and added new client-side requirements aimed at web skimming. Version 4.0.1 followed in June 2024 as an errata and clarification revision that added no new requirements, and v4.0 was retired on December 31, 2024, leaving v4.0.1 as the only active version from January 1, 2025. The compliance burden date that matters is March 31, 2025, when a large tranche of future-dated requirements became mandatory in every assessment with no grace period. Sources cite 51, 53, or 64 future-dated requirements depending on how service-provider-only and multi-part items are counted, so the defensible fact to anchor on is the March 31, 2025 deadline itself, which is not in dispute. You can read the PCI Security Standards Council guidance on the e-commerce requirements for the official position.

Two of those future-dated requirements exist specifically to counter payment-page skimming, and they carry the heaviest practical load for online retailers. Requirement 6.4.3 requires that every script loaded and executed on the payment page in the consumer's browser is inventoried, justified in writing, authorized, and integrity-checked, and because tag managers, analytics vendors, and chat widgets push updates constantly, the inventory has to be maintained continuously rather than once. Requirement 11.6.1 requires a change-and-tamper detection mechanism that alerts staff to unauthorized modification of the payment page and its HTTP headers as received by the browser, evaluated at least weekly or at a frequency justified by a targeted risk analysis. Both requirements exist because Magecart-style attacks never touch the merchant's servers in a way that traditional server-side monitoring can see.

Magecart and web skimming

Magecart is the umbrella name for dozens of threat groups that inject JavaScript card skimmers into e-commerce checkout pages, a technique that dates to at least 2015. Two variants dominate: direct compromise of the merchant's own site, often through an unpatched platform such as an older Magento installation, and supply chain compromise of a third-party script provider, which lets a single injection reach thousands of stores at once. The Volusion compromise of 2019 affected roughly 6,500 merchant stores by researcher estimates, and the pattern is best understood as breadth rather than depth, with tens of thousands of compromised stores active at any moment across the past decade.

The two most consequential single victims came from the same year. British Airways had card and personal data skimmed from its site in 2018, and the UK Information Commissioner's Office (ICO) ultimately fined the airline £20 million, with the ICO British Airways penalty notice placing the potentially affected population in the range of roughly 380,000 to 429,000 people. Ticketmaster UK was skimmed in 2018 through a compromised Inbenta chatbot script and drew a £1.25 million ICO fine issued in November 2020. The class matters for retail specifically because the attack surface is the checkout page, which only e-commerce operates at scale.

GDPR and CCPA exposure for retailers

Retailers that process European personal data face administrative fines under the General Data Protection Regulation (GDPR) of up to €20 million or 4% of global annual turnover, whichever is higher, along with 72-hour breach notification duties. Beyond the British Airways fine, the ICO fined Marriott £18.4 million in October 2020 over the Starwood breach.

In France the data protection regulator has been the most aggressive against retail. The CNIL fined the Irish entity of the SHEIN group €150 million on September 1, 2025 for depositing advertising cookies without consent. That penalty is an ePrivacy cookie enforcement action against Infinite Styles Services Co. Limited under the French Data Protection Act, not a data breach fine, and it should not be confused with SHEIN's 2018 Zoetop breach covered later in this list.

In the United States, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act, gives consumers a private right of action for breaches of unencrypted personal information with statutory damages of $100 to $750 per consumer per incident, which is the single largest driver of US retail breach class actions because it removes the need to prove individual harm. Enforcement is escalating: the California Privacy Protection Agency fined the clothing retailer Todd Snyder $345,178 in May 2025 over a broken opt-out mechanism and over-collection of identity documents. The California Attorney General's $1.2 million Sephora settlement in August 2022 remains the template retail enforcement action, and our overview of how to prevent data breaches covers the controls regulators now expect.

Latest sector statistics

The retail threat picture increasingly runs through suppliers, and the numbers reflect it. The Verizon 2026 Data Breach Investigations Report counts 806 confirmed breaches in the retail vertical, and while its report-wide findings that vulnerability exploitation reached 31% of breaches, third-party involvement rose to about 48%, and the human element featured in 62% span all sectors rather than retail alone, the third-party figure is the most retail-relevant given how much recent retail breach history runs through vendors and cloud platforms. You can review the Verizon DBIR for the full dataset.

On cost, the IBM Cost of a Data Breach Report 2025 put the global average at $4.44 million, the first year-over-year decline in five years, and its industry breakdown placed the retail sector average at $3.54 million, well below healthcare at $7.42 million and financial services at $5.56 million. Retail was one of a small group of sectors that saw breach cost rise year over year even as most declined, and its below-average absolute cost reflects lower regulated per-record value rather than lower breach frequency.

31 biggest data breaches in retail and e-commerce

The incidents below are ranked primarily by records affected, with disputed and attacker-claimed figures flagged where they appear. Read the flags carefully, because several of the largest headline numbers describe scraped data points or attacker listings rather than confirmed customer records. For cross-sector context beyond retail, see our wider roundup of the biggest data breaches.

1. Alibaba (Taobao)

  • Records affected: Roughly 1.1 billion data points scraped, per Chinese court records. Estimated and widely misreported. This was a scraping incident, not a database exfiltration, and the figure counts data points harvested rather than distinct users.
  • Date of breach: November 2019 to July 2020
  • Date disclosed: June 2021, when Chinese state media reported the Hangzhou court verdict
  • Country: China
  • Sub-sector: E-commerce marketplace
  • Attack vector: Automated web scraping. An affiliate marketing consultant built crawler software that harvested publicly displayed data from Taobao over roughly eight months.
  • Data types exposed: Usernames, mobile phone numbers, and customer comments displayed on Taobao listings. No passwords or payment data were reported taken.

A developer and his employer ran a crawler against Alibaba's Taobao shopping site, collecting user IDs, phone numbers, and comments before Alibaba detected the activity and reported it to police, and both men received suspended three-year sentences. The incident is routinely cited as one of the largest exposures in history, but nothing was stolen from a database and the scraped fields were data the platform itself displayed. It matters because it shows that for marketplaces, the exposure surface is defined by what the platform publishes at scale, not only by what it stores.

Aftermath: Criminal convictions in China with suspended sentences, and no regulatory fine against Alibaba for this incident.
Source: Reuters coverage of the Taobao scraping case

2. Ticketmaster and Live Nation (Snowflake campaign)

  • Records affected: 560 million customers. Attacker-claimed. The figure comes from a ShinyHunters BreachForums listing offering 1.3 TB of data for $500,000 and has never been confirmed by Live Nation, whose SEC Form 8-K stated no number.
  • Date of breach: April 2024, with unauthorized activity identified on May 20, 2024
  • Date disclosed: May 31, 2024, via a Live Nation SEC 8-K filing
  • Country: United States, with customers globally
  • Sub-sector: Ticketing and event e-commerce
  • Attack vector: Third-party cloud data warehouse. Attackers used infostealer-harvested credentials to log into a Snowflake customer instance that lacked multi-factor authentication, one of roughly 165 organizations hit in the same campaign that Mandiant tracks as UNC5537.
  • Data types exposed: Names, email addresses, phone numbers, postal addresses, order history, and partial payment card data including last four digits and expiry dates, per the attacker listing and notifications. Full card numbers and CVVs were not reported taken.

ShinyHunters listed a Ticketmaster dataset for sale, published samples, and later leaked barcode data for high-profile tours to pressure Live Nation, which confirmed unauthorized activity in a third-party cloud database environment. The failure was not in Ticketmaster's own perimeter but in single-factor authentication on a cloud data warehouse tenant, which makes it the defining example of consumer-facing third-party software risk.

Aftermath: US class actions were consolidated in the Central District of California, Australia's privacy regulator and others opened inquiries, and the Department of Justice charged alleged Snowflake-campaign actors Connor Moucka and John Binns in November 2024, with Moucka arrested in Canada.
Source: Live Nation SEC Form 8-K | Mandiant analysis of UNC5537

3. Adobe

  • Records affected: 153 million user accounts, per analysis of the leaked dump by security researchers and Have I Been Pwned. Figure revised upward multiple times. Adobe initially said 2.9 million, then at least 38 million active accounts.
  • Date of breach: September 2013
  • Date disclosed: October 3, 2013, with revised figures through late 2013
  • Country: United States, global user base
  • Sub-sector: Software and digital commerce, commonly included in retail roundups because Adobe now sells the Adobe Commerce and Magento platforms
  • Attack vector: Intrusion into Adobe's network with exfiltration of customer databases and product source code.
  • Data types exposed: Adobe IDs, encrypted passwords, encrypted payment card numbers and expiry dates, and password hints stored in plaintext.

Attackers took a customer database of 153 million records plus source code for several products. Adobe encrypted passwords with 3DES in ECB mode using a single key rather than salting and hashing them, so identical passwords produced identical ciphertext, and the plaintext hints stored alongside let researchers reconstruct enormous numbers of passwords. Credential reuse from this dump fueled account takeover across the wider e-commerce ecosystem for years.

Aftermath: Adobe paid $1.1 million in legal fees and an undisclosed amount to consumers to settle claims from 15 state attorneys general, plus a separate class action settlement.
Source: Krebs on Security on the Adobe breach | Have I Been Pwned, Adobe

4. Under Armour (MyFitnessPal, 2018)

  • Records affected: Roughly 150 million user accounts, stated by Under Armour.
  • Date of breach: February 2018, discovered March 25, 2018
  • Date disclosed: March 29, 2018
  • Country: United States, global user base
  • Sub-sector: Sportswear and apparel retail, consumer app
  • Attack vector: Unauthorized access to the MyFitnessPal application database. Under Armour did not detail the initial access method.
  • Data types exposed: Usernames, email addresses, and hashed passwords. Most passwords used bcrypt, but a subset used the much weaker SHA-1. Payment data was processed separately and was not affected.

Under Armour disclosed that an unauthorized party acquired data tied to roughly 150 million accounts, at the time one of the largest single-application breaches ever reported. The disclosure was praised for speed, coming four days after discovery, but criticized for the inconsistent hashing that left the SHA-1 subset trivially crackable. The dataset later circulated on dark web markets.

Aftermath: Under Armour's share price fell on disclosure, and the company compelled arbitration under its terms of service, which limited its exposure. No major regulatory fine was reported.
Source: Reuters on the MyFitnessPal breach

5. eBay

  • Records affected: 145 million user accounts.
  • Date of breach: Late February to early March 2014
  • Date disclosed: May 21, 2014
  • Country: United States, global user base
  • Sub-sector: E-commerce marketplace
  • Attack vector: Compromise of a small number of employee login credentials, giving attackers access to eBay's corporate network and then a user database. The intrusion went undetected for roughly two months.
  • Data types exposed: Names, encrypted passwords, email addresses, physical addresses, phone numbers, and dates of birth. eBay said financial data was held separately by PayPal.

Attackers used stolen employee credentials to move into eBay's network and copy a database covering all 145 million active accounts, and eBay asked every user to reset their password. The handling drew criticism because eBay took a fortnight to notify after discovery and the reset prompt was slow to reach many users. It stands as the largest pure marketplace account compromise of its era and an early sign that credential theft against employees, not payment terminals, would become the dominant retail attack path.

Aftermath: Investigations by three state attorneys general, the ICO, and the Luxembourg data protection authority followed, but no material fine was imposed, which is often cited as an example of pre-GDPR regulatory weakness.
Source: BBC coverage of the eBay breach

6. TJX Companies (TJ Maxx, Marshalls, HomeGoods)

  • Records affected: 45.7 million payment cards per TJX's own SEC filings, and more than 94 million per court filings by Visa, Mastercard, and banking plaintiffs. Figure disputed. TJX never accepted the 94 million number.
  • Date of breach: July 2005 to December 2006, with some intrusions dating to 2003
  • Date disclosed: January 17, 2007
  • Country: United States, with victims also in Canada, the UK, and Ireland
  • Sub-sector: Off-price apparel and home goods retail
  • Attack vector: Wireless network compromise. Attackers led by Albert Gonzalez cracked weak WEP encryption on store wireless networks, then pivoted into central systems and installed sniffers to capture card data over an eighteen-month period.
  • Data types exposed: Payment card magnetic stripe track data, card numbers, and expiry dates, plus driver's licence and Social Security numbers for roughly 451,000 customers who had returned merchandise without receipts.

TJX ran WEP long after the industry had moved to stronger encryption and stored full track data against PCI rules, and Gonzalez's crew sat inside the network for a year and a half. For nearly seven years it was the largest retail breach on record, and it is the reason PCI DSS compliance became a board-level topic and directly informed card-data retention prohibitions.

Aftermath: TJX booked charges of roughly $256 million, settled with Visa issuers for up to $40.9 million and Mastercard issuers for up to $24 million, paid roughly $9.75 million to 41 state attorneys general, and settled a consumer class action. Gonzalez was sentenced to 20 years in federal prison in 2010.
Source: US Department of Justice on the Gonzalez sentencing | Wired on the TJX wireless hack

7. Under Armour (2026 Everest leak)

  • Records affected: 72.7 million unique email addresses, per Have I Been Pwned, which loaded the dataset on January 21, 2026. Attributed to Have I Been Pwned, not to Under Armour. The Everest ransomware group separately claimed 343 GB of data, and Under Armour has not confirmed a figure.
  • Date of breach: Claimed by Everest in November 2025, data published January 18, 2026
  • Date disclosed: January 21, 2026, via Have I Been Pwned, with Under Armour acknowledging an investigation on January 22, 2026
  • Country: United States, global customer base
  • Sub-sector: Sportswear and apparel retail
  • Attack vector: Not confirmed. Everest has repeatedly used stolen credentials and third-party access, and Under Armour has not published a root cause.
  • Data types exposed: Per Have I Been Pwned's analysis, email addresses, names, dates of birth, genders, geographic locations, and purchase information. Under Armour said it had no evidence that passwords or payment systems were affected.

Everest listed Under Armour on its leak site in November 2025 and, after extortion failed, published the dataset to a cybercrime forum, which Troy Hunt loaded into Have I Been Pwned three days later. That notification reached roughly 72 million subscribers before the company confirmed anything, a pattern that became routine in 2025 and 2026. It is the second nine-figure-scale exposure associated with Under Armour after MyFitnessPal.

Aftermath: Under Armour said it was investigating and reported no evidence of password or payment compromise, with US class action filings following in the first quarter of 2026 and regulatory outcomes still pending as of August 2026.
Source: Have I Been Pwned, Under Armour | TechCrunch on the Under Armour breach claims

8. Target

  • Records affected: 40 million payment card records plus personal information for up to 70 million additional customers. Figure revised upward; Target added the 70 million figure on January 10, 2014, three weeks after the initial announcement.
  • Date of breach: November 27 to December 15, 2013, the peak of the holiday shopping season
  • Date disclosed: December 18, 2013, by Brian Krebs, confirmed by Target on December 19, 2013
  • Country: United States, plus a smaller number of Canadian customers
  • Sub-sector: Mass merchandise and grocery retail
  • Attack vector: Third-party supplier compromise leading to POS malware. Attackers phished credentials from Fazio Mechanical Services, an HVAC contractor with vendor-portal access, then moved into the payment network and deployed RAM-scraping malware to about 1,800 stores.
  • Data types exposed: Full magnetic stripe track data, card numbers, expiry dates, CVVs, and encrypted PINs for 40 million cards, plus names, addresses, phone numbers, and email addresses for up to 70 million people.

Target's FireEye deployment generated alerts during the intrusion and its Bangalore security team escalated them, but the alerts were not acted on in Minneapolis, which made Target the canonical case study in why detection without response is worthless. The breach became the single most important driver of the US migration to EMV chip cards and made third-party vendor access a mainstream board-level risk.

Aftermath: CEO Gregg Steinhafel and CIO Beth Jacob both departed, and Target reported gross breach costs of roughly $292 million. Settlements included $39 million to banks and credit unions, $67 million to Visa issuers, an $18.5 million multistate settlement with 47 state attorneys general and the District of Columbia in May 2017, then the largest of its kind, and a $10 million consumer class settlement.
Source: California Attorney General on the $18.5 million Target settlement | Krebs on Security on the Target HVAC vector

9. Hot Topic (with BoxLunch and Torrid)

  • Records affected: Roughly 57 million unique email addresses, per Have I Been Pwned, which loaded 56,904,909 accounts. Attributed to Have I Been Pwned. The threat actor "Satanic" separately claimed 350 million records, which is not supported by the dataset, and Hot Topic did not confirm a number.
  • Date of breach: October 2024, with the listing appearing October 21, 2024
  • Date disclosed: Publicly surfaced October 21, 2024; Have I Been Pwned notified users in November 2024
  • Country: United States
  • Sub-sector: Specialty apparel and pop culture merchandise retail
  • Attack vector: Infostealer malware and a cloud account without multi-factor authentication. Researchers at Hudson Rock traced the likely entry to credentials harvested from an employee device at Robling, a retail analytics vendor. Reported by researchers, not confirmed by Hot Topic.
  • Data types exposed: Email addresses, physical addresses, phone numbers, dates of birth, purchase histories, and partial payment card data, with records reportedly dating back to 2011 across the Hot Topic, BoxLunch, and Torrid brands.

"Satanic" tried to sell the data on BreachForums for $20,000 and separately tried to extort $100,000 from Hot Topic, which did not issue a substantive public statement, so Have I Been Pwned again became the effective notification channel. It stands as one of the largest US retail breaches by raw account count and another case where a mid-tier analytics vendor, not the retailer, was the entry point.

Aftermath: Class actions were filed in federal court, and Hot Topic's silence drew criticism likely to feature in state attorney general scrutiny.
Source: BleepingComputer on the Hot Topic notification | Have I Been Pwned

10. The Home Depot

  • Records affected: 56 million payment cards and 53 million email addresses.
  • Date of breach: April to September 2014
  • Date disclosed: September 2, 2014, by Brian Krebs, confirmed by Home Depot on September 8, 2014
  • Country: United States and Canada
  • Sub-sector: Home improvement retail
  • Attack vector: Third-party vendor credentials leading to POS malware. Attackers used stolen vendor credentials to enter the network, escalated privileges, and installed custom memory-scraping malware on self-checkout terminals.
  • Data types exposed: Payment card data from 56 million cards and 53 million customer email addresses.

The malware ran undetected on self-checkout systems for roughly five months, making it larger than Target by card count, and later reporting described an under-resourced security program running outdated antivirus. Home Depot accelerated its rollout of EMV chip-and-PIN terminals and point-to-point encryption, reinforcing the lesson that unchecked third-party access plus flat internal networks equals estate-wide POS compromise.

Aftermath: Home Depot reported gross breach costs of roughly $298 million before insurance, paid a $19.5 million consumer class settlement, $25 million to financial institutions, roughly $27.25 million to Visa and Mastercard issuers, and a $17.5 million multistate settlement with 46 state attorneys general and the District of Columbia in November 2020.
Source: California Attorney General on the $17.5 million Home Depot settlement | Krebs on Security on the Home Depot breach

11. SHEIN and ROMWE (Zoetop Business Company)

  • Records affected: 39 million SHEIN accounts and 7 million ROMWE accounts, roughly 46 million in total, including more than 800,000 New York residents.
  • Date of breach: June 2018
  • Date disclosed: Partially disclosed by SHEIN in 2018 with an understated scope; the full scale was established by the New York Attorney General and announced on October 12, 2022
  • Country: Hong Kong-based operator, with customers in the United States and globally
  • Sub-sector: Fast fashion e-commerce
  • Attack vector: Intrusion into Zoetop's systems. The New York Attorney General found Zoetop failed to maintain reasonable security, including adequate password management, monitoring, and incident response.
  • Data types exposed: Login credentials including email addresses and passwords hashed with weak MD5 and a short salt, plus credit card information for a subset of customers.

Zoetop, then the parent of both brands, learned of the breach in 2018 but contacted only a fraction of affected users, and the New York Attorney General found that more than 32.5 million accounts were never told their credentials had been stolen while the company misrepresented the scope publicly. This is the most instructive retail case on breach response conduct rather than breach cause, because the penalty was driven almost entirely by what the company said and failed to say afterward.

Aftermath: A $1.9 million settlement with the New York Attorney General in October 2022, plus injunctive terms on security, password hashing, and incident response. Separately, and unrelated to this breach, the CNIL fined SHEIN's Irish entity €150 million in September 2025 over cookie consent.
Source: New York Attorney General on the Zoetop settlement | CNIL on the SHEIN cookie fine

12. Panera Bread (2018 API exposure)

  • Records affected: Roughly 37 million customer records. Estimated and disputed. The figure derives from enumeration of sequential record IDs by researcher Dylan Houlihan and Brian Krebs; Panera claimed fewer than 10,000 customers were affected and never published a confirmed figure.
  • Date of breach: Exposed from at least August 2017 until April 2, 2018. This was a public exposure, not a confirmed exfiltration.
  • Date disclosed: April 2, 2018, when Brian Krebs published, eight months after the private report
  • Country: United States
  • Sub-sector: Food retail and quick-service restaurant e-commerce
  • Attack vector: Insecure direct object reference in an unauthenticated web API. Records returned in plaintext with sequential IDs, so the entire customer base could be enumerated by incrementing a number in a URL.
  • Data types exposed: Names, email addresses, physical addresses, dates of birth, the last four digits of payment cards, and loyalty card numbers carrying stored value.

Houlihan reported the flaw to Panera's then-CIO in August 2017 and was accused of running a scam, and Panera took no effective action for eight months. When Krebs published, Panera briefly took the site down and told reporters the issue was resolved, while researchers showed the endpoint was still leaking. It remains the definitive retail case study in mishandled vulnerability disclosure, and the flaw class, broken object level authorization, still tops the OWASP API Security Top 10.

Aftermath: Reputational damage and sustained criticism rather than regulatory penalty, with no significant fine reported.
Source: Krebs on Security on the Panera leak

13. Coupang

  • Records affected: 33.7 million user accounts, confirmed by the company and by South Korea's Personal Information Protection Commission. Figure revised upward from an initial estimate of roughly 4,500 individuals.
  • Date of breach: Unauthorized access began June 24, 2025, discovered November 18, 2025
  • Date disclosed: November 30, 2025
  • Country: South Korea
  • Sub-sector: E-commerce marketplace and online grocery
  • Attack vector: Unauthorized access via overseas servers. Coupang told the SEC on December 15, 2025, that a former employee was responsible. Insider attribution is company-stated and subject to ongoing investigation.
  • Data types exposed: Names, email addresses, postal addresses, phone numbers, and order histories. Coupang stated that no financial information or passwords were compromised.

Access persisted for roughly five months before detection, and the first public estimate of 4,500 affected individuals was revised to more than 33 million within days, which became a major part of the scandal in Korea. As the country's largest online retailer, the breach touched a majority of the adult population, making it the largest consumer data breach in South Korean history.

Aftermath: Coupang announced compensation vouchers worth 50,000 won per affected customer, a program valued at roughly $1.17 billion, and on June 11, 2026, the Personal Information Protection Commission imposed a record fine of 624.9 billion won, roughly $409 million at the time, the largest privacy penalty in South Korean history.
Source: SecurityWeek on the Coupang voucher program | Cybernews on the Coupang breach

14. Neiman Marcus Group (2013 and 2024)

  • Records affected: 2013: roughly 350,000 cards confirmed exposed and about 9,200 confirmed fraudulently used, revised from an initial 1.1 million estimate. 2024: Neiman Marcus formally notified 64,472 people, while Have I Been Pwned found more than 31 million unique email addresses in the leaked dataset. The gap is unresolved and both carry their source.
  • Date of breach: 2013: July to October 2013. 2024: April 14 to May 24, 2024.
  • Date disclosed: 2013: January 10, 2014, by Brian Krebs. 2024: late June 2024 after threat actor "Sp1d3r" listed the data.
  • Country: United States
  • Sub-sector: Luxury department store retail
  • Attack vector: 2013: POS memory-scraping malware. 2024: the Snowflake campaign, using infostealer-harvested credentials against a tenant lacking multi-factor authentication.
  • Data types exposed: 2013: payment card data. 2024: names, contact details, dates of birth, and gift card numbers without PINs.

Neiman Marcus is a rare retailer that appears in both the POS malware era and the cloud third-party era, which makes it a useful bookend. In 2024 it was caught in the same Snowflake campaign as Ticketmaster and Advance Auto Parts, and the order-of-magnitude gap between the 64,472 people it notified and the 31 million email addresses found in the dump is one of the clearest illustrations of how legal notification thresholds and actual exposure diverge.

Aftermath: 2013: a $1.6 million settlement with 43 state attorneys general and the District of Columbia in January 2019, plus a $1.5 million consumer class settlement. 2024: class actions filed in the Northern District of Texas, since settled.
Source: BleepingComputer on the Neiman Marcus Snowflake breach | BleepingComputer on 31 million exposed email addresses

15. Wawa

  • Records affected: More than 30 million US payment cards plus roughly one million international cards, based on Gemini Advisory's analysis of the Joker's Stash listing reported by Brian Krebs. The multistate attorneys general separately found that potentially 34 million cards were compromised. Estimated; Wawa did not publish a card count.
  • Date of breach: Malware present from March 4, 2019, with card exposure running April 18 to December 12, 2019
  • Date disclosed: December 19, 2019
  • Country: United States, all roughly 850 Wawa locations
  • Sub-sector: Convenience store and fuel retail
  • Attack vector: POS malware on in-store payment processing servers and fuel dispenser terminals.
  • Data types exposed: Payment card numbers, expiry dates, and cardholder names. Wawa said debit card PINs and CVV2 numbers were not affected.

Malware sat on Wawa's payment servers for roughly nine months across the entire estate, and in January 2020 the Joker's Stash marketplace began uploading the trove, which is how the scale became public. It is one of the last very large POS malware breaches in the United States, exploiting the extended EMV deadline that left fuel dispensers processing magnetic stripe transactions.

Aftermath: An $8 million multistate settlement co-led by New Jersey and Pennsylvania in July 2022, plus a consumer class settlement valued at up to $9 million and a separate settlement with financial institutions.
Source: New Jersey Attorney General on the Wawa settlement | Krebs on Security on the Wawa breach

16. Dixons Carphone (Currys PC World)

  • Records affected: 5.9 million payment cards and, after revision, personal data for roughly 10 million customers. Figure revised upward from an initial estimate of 1.2 million personal data records.
  • Date of breach: July 2017 to April 2018
  • Date disclosed: June 13, 2018, with the revision to 10 million on July 31, 2018
  • Country: United Kingdom
  • Sub-sector: Electronics and telecoms retail
  • Attack vector: POS malware installed on 5,390 tills. The ICO found inadequate patching, no local firewalls, and poor segregation and logging.
  • Data types exposed: Payment card data from 5.9 million cards, mostly chip-and-PIN protected, plus around 105,000 non-EU cards without that protection, and names, addresses, and email addresses for roughly 10 million people.

Attackers ran malware across more than 5,000 tills for nine months, and the ICO's investigation under the pre-GDPR Data Protection Act 1998 found systemic failures in basic hygiene. It is the largest UK retail POS compromise on record, and the pre-GDPR legal basis capped the penalty at £500,000, a figure the ICO explicitly noted was the maximum available.

Aftermath: A £500,000 ICO fine in January 2020, the maximum permitted under the Data Protection Act 1998. Dixons Carphone contested the penalty through a multi-year appeal: the First-tier Tribunal reduced it to £250,000 in 2022 and the Upper Tribunal later sided with the company, before the ICO won at the Court of Appeal in February 2026. The company was renamed Currys plc.
Source: ICO on the DSG Retail Court of Appeal ruling

17. JD Sports

  • Records affected: Roughly 10 million customers.
  • Date of breach: Data from online orders placed between November 2018 and October 2020; unauthorized access identified in January 2023
  • Date disclosed: January 30, 2023
  • Country: United Kingdom
  • Sub-sector: Sportswear and footwear retail
  • Attack vector: Unauthorized access to a server holding historic online order data across several brands. JD Sports did not publish a root cause.
  • Data types exposed: Names, billing and delivery addresses, email addresses, phone numbers, order details, and the final four digits of payment cards. Full card data and passwords were not held on the affected system.

JD Sports disclosed that a server containing two years of legacy order history had been accessed, and the most notable feature is the data retention question, because the records were between two and four years old at the time of the breach. It is a useful entry precisely because there is no exotic technique to distract from the governance failure of retaining accessible order data for 10 million customers.

Aftermath: The ICO was notified, and no public enforcement action had been reported as of August 2026.
Source: BBC on the JD Sports breach

18. Co-operative Group (Co-op)

  • Records affected: 6.5 million members, the entirety of the Co-op membership, confirmed by chief executive Shirine Khoury-Haq.
  • Date of breach: April 2025
  • Date disclosed: Attack acknowledged April 30, 2025; the full figure confirmed by the CEO in July 2025
  • Country: United Kingdom
  • Sub-sector: Grocery, convenience, and funeral care retail
  • Attack vector: Social engineering attributed to Scattered Spider, consistent with the wider 2025 UK retail campaign. Attackers reset credentials via help desk impersonation, and DragonForce ransomware affiliates were associated with the campaign.
  • Data types exposed: Names, contact details, residential addresses, email addresses, phone numbers, and dates of birth for all members. Co-op confirmed that passwords, bank details, and payment card data were not accessed.

Co-op detected the intrusion and took systems offline pre-emptively, which limited the damage relative to Marks and Spencer but caused significant logistics disruption, including empty shelves in remote communities where it is the only grocer. The CEO's early public apology and willingness to confirm the full figure stand in contrast to the disclosure practice of several other retailers caught in the same wave of UK data breaches.

Aftermath: Co-op assessed revenue losses of roughly £206 million and a profit impact of around £80 million. The Cyber Monitoring Centre classified the Marks and Spencer and Co-op incidents together as a single combined event with an estimated UK economic impact of £270 million to £440 million. Four people were arrested by the National Crime Agency in July 2025 in connection with the attacks.
Source: Computer Weekly on the Co-op breach | National Crime Agency on the arrests

19. Panera Bread (2026 ShinyHunters breach)

  • Records affected: 5.1 million unique email addresses with associated personal data, plus data for more than 26,000 employees. Attacker-derived and researcher-analysed. The figure comes from analysis of the leaked archive; Panera confirmed a breach but published no count.
  • Date of breach: January 2026
  • Date disclosed: Publicly reported February 2, 2026, after ShinyHunters published a compressed archive
  • Country: United States
  • Sub-sector: Food retail and quick-service restaurant
  • Attack vector: Reported as a stolen Microsoft Entra single sign-on session obtained through voice phishing of the IT help desk, consistent with the ShinyHunters and Scattered Spider playbook. Reported, not confirmed by Panera.
  • Data types exposed: Email addresses, names, phone numbers, and physical addresses for customers, and broader personal data for employees.

ShinyHunters gained access to Panera's corporate environment, exfiltrated data, demanded a ransom, and published the archive when Panera declined to pay, with Panera confirming that the data involved was contact information and that authorities had been notified. This is Panera's second major exposure after the 2018 API leak, and the two together illustrate how the retail threat model shifted from insecure web endpoints to identity provider abuse in under a decade.

Aftermath: US class actions were filed in early 2026, and the regulatory position was still developing as of August 2026.
Source: Fox News on the Panera breach | Have I Been Pwned, Panera Bread

20. Saks Fifth Avenue and Lord and Taylor (Hudson's Bay Company)

  • Records affected: More than 5 million payment cards offered for sale, per Gemini Advisory's analysis of the Joker's Stash listing. Attacker-listed figure; Hudson's Bay did not confirm a number.
  • Date of breach: May 2017 to March 2018
  • Date disclosed: April 1, 2018, after the Joker's Stash listing
  • Country: United States and Canada
  • Sub-sector: Luxury and mid-market department store retail
  • Attack vector: POS malware attributed to the FIN7 criminal group, which also operated the Joker's Stash listing. Initial access was consistent with FIN7's spear-phishing of corporate staff.
  • Data types exposed: Payment card track data from in-store transactions. Hudson's Bay said there was no indication that online transactions were affected.

FIN7 compromised the entire Lord and Taylor store network and 83 Saks Fifth Avenue locations for roughly ten months, then began selling the cards in tranches. It demonstrated that a decade after TJX, US specialty retail POS estates were still being harvested at scale by a professionalized criminal organization operating through the fake security company Combi Security.

Aftermath: Class actions in the US and Canada, and several FIN7 leaders were convicted, including Fedir Hladyr, sentenced to 10 years in 2021.
Source: Gemini Advisory on the FIN7 Saks and Lord and Taylor hack | US Department of Justice on the FIN7 sentencing

21. Marks and Spencer

  • Records affected: No precise record count was ever published. Marks and Spencer confirmed that some personal customer data was taken and wrote to customers, but never stated how many people were affected. What it quantified was financial: an expected impact of roughly £300 million on group operating profit for 2025/26 before mitigation.
  • Date of breach: Initial compromise reported as early as February 2025, with the disruptive phase beginning around April 17 to 25, 2025
  • Date disclosed: Incident acknowledged April 22, 2025; theft of personal data confirmed by CEO Stuart Machin on May 13, 2025
  • Country: United Kingdom
  • Sub-sector: Department store, clothing, home, and food retail
  • Attack vector: Social engineering of an outsourced IT service desk. Chairman Archie Norman told a parliamentary committee that attackers impersonated an employee and had a third-party service desk perform a password reset, bypassing multi-factor authentication. Activity is attributed to Scattered Spider with DragonForce ransomware deployed against VMware ESXi hosts, from reporting and law enforcement briefings rather than a company root cause.
  • Data types exposed: Names, dates of birth, home and email addresses, phone numbers, household information, and online order histories. Payment card details were not held on the affected systems, and passwords were not taken, though the company forced a password reset as a precaution.

This was the most consequential retail cyber incident in the United Kingdom in a decade. Marks and Spencer suspended online ordering for roughly six weeks, saw contactless payment and click-and-collect fail in stores, and reverted parts of its food supply chain to manual processes. The attack path was mundane, a help desk password reset for a plausible-sounding caller, and that is precisely why it reset the sector's understanding of identity and outsourcing risk.

Aftermath: The roughly £300 million figure is the guided hit to 2025/26 group operating profit before mitigation, not the net or final cost. The company signalled it expected to roughly halve that through cost actions and an insurance claim of up to about £100 million. The Cyber Monitoring Centre classified the Marks and Spencer and Co-op attacks together as a single event with an estimated UK economic impact of £270 million to £440 million. Four people were arrested by the National Crime Agency in July 2025, and the company gave evidence to the House of Commons Business and Trade Committee.
Source: TechCrunch on the Marks and Spencer breach | BleepingComputer on the Scattered Spider link

22. Harrods

  • Records affected: Up to roughly 430,000 customer records in the September 2025 incident. Precise wording matters: Harrods told customers that the threat actor claimed to have taken data relating to up to 430,000 records. This is a Harrods-relayed attacker claim, not a verified count. The May 2025 intrusion attempt resulted in no confirmed customer data loss.
  • Date of breach: Two events in 2025. An attempted intrusion around May 1, 2025, and a third-party provider compromise disclosed at the end of September 2025.
  • Date disclosed: May 1, 2025, for the first incident; September 26 to 27, 2025, for the second
  • Country: United Kingdom
  • Sub-sector: Luxury department store retail
  • Attack vector: May 2025: unauthorized access attempts against Harrods' internal systems, part of the same Scattered Spider-linked campaign. September 2025: compromise of an unnamed third-party service provider.
  • Data types exposed: September 2025: names, email addresses, telephone numbers, and postal addresses for online customers. No passwords or payment card data were involved.

Harrods is the clearest demonstration that containment works. In May 2025 it detected intrusion attempts and restricted internet access across its sites, reporting no data compromise, in contrast to Marks and Spencer's lost six weeks of trading. Four months later it was caught anyway through a supplier, which separates the two failure modes neatly: your own identity perimeter, and everyone you have handed customer data to.

Aftermath: Harrods described the September incident as isolated and contained, said it would not engage with the attackers, and notified the ICO. Four people were arrested by the National Crime Agency in July 2025, and no fine had been reported as of August 2026.
Source: BleepingComputer on the Harrods breach | National Crime Agency on the arrests

23. Adidas

  • Records affected: No confirmed figure for the May 2025 incident. Adidas said data of customers who had contacted its help desk was accessed but published no count. A separate February 2026 claim alleged roughly 815,000 records from a third party; that figure is claimed and unverified, and Adidas said it was investigating.
  • Date of breach: May 2025 for the main disclosure, with related incidents in Turkey and South Korea earlier in 2025 and a further third-party claim in February 2026
  • Date disclosed: May 27, 2025
  • Country: Germany, with affected customers across multiple markets
  • Sub-sector: Sportswear and footwear retail
  • Attack vector: Compromise of a third-party customer service provider. Adidas did not name the provider or publish an access method.
  • Data types exposed: Names, email addresses, and telephone numbers of consumers who had contacted the help desk. No payment or password data was affected.

Adidas disclosed that an unauthorized party obtained consumer contact data through a third-party customer service provider, weeks after reporting similar compromises affecting its Turkish and South Korean operations. That made the pattern the story rather than the single event, because one outsourced contact-centre relationship, replicated across regions, produced repeated exposure of the same data class.

Aftermath: Adidas notified regulators and law enforcement and began contacting affected consumers, with no fine reported as of August 2026 and the February 2026 claim unresolved.
Source: SecurityWeek on the Adidas vendor breach | The Register on the 2026 Adidas claim

24. LVMH luxury brands (Dior, Louis Vuitton, and Tiffany)

  • Records affected: More than 5.5 million customers across the three brands, per South Korea's Personal Information Protection Commission. Treat 5.5 million as the regulator-stated aggregate for the Korean enforcement action rather than a global total, since UK, Turkish, and US populations were disclosed separately.
  • Date of breach: Unauthorized access to a Dior client database dated to January 26, 2025, with Louis Vuitton Korea, Louis Vuitton UK, and further subsidiaries affected through roughly May to July 2025
  • Date disclosed: Rolling disclosures from May 2025, with Louis Vuitton UK disclosing in July 2025
  • Country: France-headquartered group, with customers in South Korea, the UK, Turkey, and the United States
  • Sub-sector: Luxury goods and jewellery retail
  • Attack vector: Compromise of third-party customer management environments, with reporting linking the activity to the ShinyHunters extortion ecosystem. Attribution is from reporting and regulator findings, not a published LVMH root cause.
  • Data types exposed: Names, email addresses, telephone numbers, postal and shipping addresses, and purchase history. No payment or financial data was held in the affected systems.

Across 2025 a sequence of intrusions hit LVMH subsidiaries one after another, each through customer-facing data platforms operated with third parties. What makes the cluster important is the regulatory outcome rather than the record count, because South Korea's regulator treated the brands as having failed to implement adequate security and issued one of the few at-scale luxury retail breach fines, placing it among the most consequential European data breaches of the year. It also shows that clienteling data is a high-value target even without card numbers.

Aftermath: On February 12, 2026, South Korea's Personal Information Protection Commission imposed a total of 36.033 billion won, roughly $25 million, plus 10.8 million won in additional penalties, split across Louis Vuitton Korea, Christian Dior Couture Korea, and Tiffany Korea. Class actions were filed in Canada and the United States.
Source: BleepingComputer on the LVMH brand fines | BleepingComputer on Dior US notifications

25. French retail cluster (Boulanger, Cultura, and Truffaut)

  • Records affected: Boulanger: 27.5 million raw records claimed by the attacker in a 16 GB file, reduced to roughly 5 million deduplicated customer entries in the filtered version. Attacker-claimed and researcher-filtered; do not read 27.5 million as a customer count. Cultura: a reported range of 1.5 to 2.6 million accounts. Truffaut: roughly 270,000 accounts.
  • Date of breach: September 2024, with a related wave continuing through late 2024
  • Date disclosed: September 2024
  • Country: France
  • Sub-sector: Consumer electronics, culture and leisure, and garden centre retail
  • Attack vector: Compromise of shared third-party infrastructure. Reporting indicated the databases originated with a subcontractor handling delivery and logistics data, which produced simultaneous exposure across several brands. A threat actor using the handle "horrormar44" claimed the Boulanger data.
  • Data types exposed: Names, postal addresses, telephone numbers, email addresses, and order or delivery notes. No banking, payment, or password data was exposed.

Within days in September 2024, customer databases from Boulanger, Cultura, and Truffaut appeared for sale and then for free on cybercrime forums, with further French retailers disclosing incidents in the following weeks. The cluster is the clearest European example of concentration risk in retail logistics, and it stands out among recent French data breaches because several competing chains handed delivery data to the same class of subcontractor, so a single supplier compromise produced a national-scale exposure.

Aftermath: The affected retailers notified the CNIL and their customers, and no fines specific to this cluster had been reported as of August 2026. The wave contributed directly to CNIL guidance on subcontractor security obligations under GDPR Article 28.
Source: The Record on the French retailer breaches | Cybernews on the Boulanger leak

26. Advance Auto Parts (Snowflake campaign)

  • Records affected: More than 2.3 million job applicants and current and former employees, per Advance Auto Parts' own notifications filed with state regulators. This was not a customer breach. It is one of the few Snowflake campaign victims with a reliable, company-notified count.
  • Date of breach: April 14 to May 24, 2024, with the company learning of it on May 23, 2024
  • Date disclosed: Notifications filed and reported in July 2024, after threat actor "Sp1d3r" listed the data in June 2024
  • Country: United States and Canada
  • Sub-sector: Automotive parts and accessories retail
  • Attack vector: Third-party cloud data warehouse. As with Ticketmaster and Neiman Marcus, attackers used infostealer-harvested credentials against a Snowflake tenant lacking multi-factor authentication, part of the UNC5537 campaign.
  • Data types exposed: Full names, Social Security numbers, driver's licence numbers, and other government identification numbers.

Advance Auto Parts was one of roughly 165 organizations caught in the 2024 Snowflake campaign, and it is the most instructive retail victim precisely because the exposed data was employment-related. Retail HR and applicant-tracking data sits in the same analytics platforms as commercial data and carries Social Security numbers that shopper records do not, which raises the identity theft severity by an order of magnitude.

Aftermath: Twelve months of credit monitoring were offered, class actions were consolidated, and a settlement followed. The wider campaign led to US charges against Connor Moucka and John Binns.
Source: BleepingComputer on the Advance Auto Parts breach | Cybersecurity Dive on the Snowflake-linked attack

27. Pandabuy

  • Records affected: Roughly 1.3 million users. The threat actors initially claimed 3 million, but analysis found the sample padded with fabricated email addresses, so the genuine dataset covered about 1.3 million accounts. The 3 million claim is disproven; the 1.3 million figure comes from the dataset analysis, not from Pandabuy.
  • Date of breach: Characterized by Pandabuy as an earlier incident; disclosed publicly March 31, 2024
  • Date disclosed: March 31 to early April 2024
  • Country: China, with a predominantly Western customer base
  • Sub-sector: Cross-border e-commerce shopping agent and reshipping platform
  • Attack vector: Exploitation of multiple vulnerabilities in the platform's API, claimed by threat actors "Sanggiero" and "IntelBroker".
  • Data types exposed: User IDs, full names, telephone numbers, email addresses, home addresses, login IP addresses, and order details.

Pandabuy buys goods on Chinese marketplaces for overseas customers and reships them, so its database links a Western identity and home address to a full purchase history. The company's initial response through a Discord administrator, calling the data old and the issue handled, drew criticism, and the dataset was loaded into Have I Been Pwned. It is the cleanest recent example of an API-layer breach at a pure e-commerce intermediary and of a threat actor inflating a record count that was then repeated uncritically.

Aftermath: No regulatory action was publicly reported, the platform continued to operate, and reporting later described extortion attempts.
Source: BleepingComputer on the Pandabuy leak | Have I Been Pwned, Pandabuy

28. Russell Cellular (Verizon authorized retailer)

  • Records affected: 6.3 million customer and employee records. Attacker-claimed and unconfirmed. The figure comes from a threat actor's forum listing of a 61 GB archive, and Russell Cellular had not confirmed a count or begun individual notifications as of the available reporting. This entry is presented entirely as an unverified claim under investigation.
  • Date of breach: Not established. The listing appeared March 17, 2026.
  • Date disclosed: Surfaced publicly in March 2026 through the listing and reporting; a plaintiffs' firm announced an investigation in April 2026
  • Country: United States
  • Sub-sector: Mobile and wireless specialty retail, more than 750 store locations
  • Attack vector: Not established or published. The claimed dataset includes employee credentials and access roles, consistent with but not proof of a credential-based intrusion.
  • Data types exposed: Per the attacker listing: names, telephone numbers, email addresses, account numbers, invoice and tracking numbers, device identifiers, contract details, and tariff plan selections, plus employee credentials. All data types are attacker-described.

A threat actor posted what it described as a 61 GB Russell Cellular dataset for sale. As an authorized Verizon retailer rather than a carrier, its records mirror carrier account data without sitting behind carrier-grade security, and the affected customer generally has no idea the retailer exists as a separate data controller. As of the available reporting the company had not notified affected individuals, which drew class action investigation notices alleging notification delay.

Aftermath: Class action investigations were announced in April 2026, with no confirmed company statement, regulatory filing, or notification program reported as of August 2026.
Source: Cybernews on the Russell Cellular claim | Schubert Jonckheer and Kolbe investigation notice

29. Michaels Stores (with Aaron Brothers)

  • Records affected: Up to roughly 2.6 million payment cards at Michaels plus roughly 400,000 at Aaron Brothers, about 3 million potentially affected in total. Michaels published these as upper bounds in its own statement.
  • Date of breach: May 8, 2013, to January 27, 2014, at Michaels; June 26, 2013, to February 27, 2014, at Aaron Brothers
  • Date disclosed: Suspicious activity announced January 2014; confirmed with figures on April 17, 2014
  • Country: United States
  • Sub-sector: Arts, crafts, and framing retail
  • Attack vector: POS malware described by the company as highly sophisticated. This was Michaels' second card breach, following a PIN pad tampering incident in 2011.
  • Data types exposed: Payment card numbers and expiry dates. Michaels said names, addresses, and PINs were not at risk.

Michaels sat in the middle of the 2013 to 2014 US POS malware wave alongside Target and Neiman Marcus, with the same disclosure pattern of a Krebs report, then a company acknowledgement, then a confirmed figure months later. It is worth including because the earlier 2011 PIN pad swap makes Michaels one of the few US retailers compromised twice by entirely different card theft techniques within three years, a reminder that fixing one card-data attack surface does not address the others.

Aftermath: Free credit monitoring was offered, and consumer class actions became part of the developing US case law on whether increased fraud risk alone confers standing. No major regulatory fine was reported.
Source: Krebs on Security on the Michaels breach | BankInfoSecurity on the Michaels confirmation

30. Dymocks Booksellers

  • Records affected: Dymocks notified roughly 836,000 customers. Separately, at least 1.24 million Booklover loyalty records were found circulating and loaded into Have I Been Pwned. Both figures carry their source; the gap is likely deduplication and legacy records.
  • Date of breach: Data circulating from at least June 2023; Dymocks became aware on September 6, 2023
  • Date disclosed: September 2023
  • Country: Australia
  • Sub-sector: Bookselling and specialty retail
  • Attack vector: Compromise of an external data partner during a loyalty-programme migration. Dymocks was alerted by Troy Hunt rather than detecting the loss itself.
  • Data types exposed: Full names, dates of birth, email addresses, postal addresses, mobile numbers, and gender for loyalty programme members. No financial data was involved.

Dymocks is the canonical migration-window breach. Customer data was in motion between an old and a new loyalty provider, and the copies created for that migration were the copies that leaked, trading publicly for roughly three months before an external researcher told the company. For a mid-sized retailer it is a more realistic cautionary tale than the nine-figure incidents, and it ranks among the most cited Australian data breaches, because the failure required no sophistication, only a temporary dataset held by a supplier during a project.

Aftermath: Dymocks notified the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme and contacted affected customers, with no penalty reported as of August 2026.
Source: BleepingComputer on the Dymocks breach | ACS Information Age on the Dymocks hack

31. Forever 21

  • Records affected: 539,207 individuals, confirmed by Forever 21's own notification letters. This is a precise, company-stated figure.
  • Date of breach: January 5 to March 20, 2023
  • Date disclosed: Notification letters sent August 29 to 31, 2023, more than five months after the intrusion ended
  • Country: United States
  • Sub-sector: Fast fashion apparel retail
  • Attack vector: Unauthorized third-party access to Forever 21's computer systems. The company did not publish an initial access method.
  • Data types exposed: Names, dates of birth, Social Security numbers, bank account numbers, and health plan information. The affected population was overwhelmingly current and former employees rather than shoppers.

Forever 21 also suffered an earlier and separate card breach in 2017 involving POS malware, but the 2023 incident matters for a different reason: it is the sharpest example that a retailer's most sensitive data is usually its HR and benefits data, not its customer data. Half a million people had Social Security numbers, bank account numbers, and health plan details exposed by a clothing retailer, a combination that supports identity theft, financial fraud, and benefits fraud at once, and none of it was protected by PCI DSS because none of it was card data.

Aftermath: One year of credit monitoring was offered, multiple class actions were filed in federal court, and the five-month notification gap became a focus of the litigation.
Source: TechCrunch on the Forever 21 breach | HIPAA Journal on the Forever 21 breach

How UpGuard helps retailers reduce breach risk

The three eras in this list point to the same conclusion: retail risk now spans a retailer's own attack surface, its vendor ecosystem, and its workforce at the same time, and treating those as separate problems is what lets a single help desk call or an unmonitored checkout script turn into an estate-wide incident. UpGuard is a cyber risk posture management platform that unifies all three surfaces so security teams can see and act on exposure in one place.

  • Breach Risk: external attack surface management and threat intelligence that discovers exposed assets, monitors for dark web exposure, and prioritizes findings using exploitation probability and known exploited vulnerability data rather than raw severity scores, which maps directly to the client-side and internet-facing exposure behind Magecart and skimming incidents.
  • Vendor Risk: third-party risk management that continuously assesses and monitors suppliers, the entry point in the Snowflake, logistics-subcontractor, and customer-service-provider breaches throughout this list.
  • User Risk: human risk management that surfaces compromised credentials and coaches employees in the moment, addressing the identity and help desk social engineering that defined the 2025 and 2026 retail campaigns.

To see how this unified view applies to your own environment, you can start a free trial of the UpGuard platform.

Frequently asked questions

What is the biggest retail data breach?

By confirmed customer scale, Coupang's 2025 breach of 33.7 million accounts is the largest verified retail incident, while Ticketmaster's attacker-claimed 560 million and Alibaba's 1.1 billion scraped data points are larger headline numbers that the companies have not confirmed.

How do retail data breaches happen?

Most fall into three patterns: point-of-sale malware that scrapes card data in stores, client-side skimming or credential theft against checkouts and cloud platforms, and social engineering that tricks a help desk into resetting an employee's access.

What was the Target data breach?

In late 2013, attackers used credentials stolen from an HVAC contractor to reach Target's payment network and deploy malware that captured 40 million payment cards and personal data for up to 70 million customers.

Is Magecart still a threat to online retailers?

Yes. Skimming groups continue to inject JavaScript into checkout pages and third-party scripts, which is why PCI DSS 4.0.1 now requires merchants to inventory payment-page scripts and detect tampering.

What is the Scattered Spider retail campaign?

Scattered Spider is the threat cluster behind the 2025 attacks on Marks and Spencer, Co-op, and Harrods, which used help desk impersonation to reset credentials and bypass multi-factor authentication rather than any technical exploit.

How can retailers prevent data breaches?

Continuously monitor your external attack surface and payment pages, assess and monitor third-party suppliers and cloud tenants for weak authentication, and treat identity and help desk processes as a primary control by requiring strong verification before any credential reset.

Related posts

Learn more about the latest issues in cybersecurity.