Retail is the most consistently targeted consumer-facing sector in the history of breach reporting, and the reason is structural. Retailers concentrate payment card data, run point-of-sale (POS) estates across thousands of stores, load high-traffic checkouts with third-party JavaScript, and depend on a deep bench of suppliers, IT outsourcers, and cloud platforms. As of August 2026, the largest and most consequential retail data breaches span three eras: the POS malware era of Target, TJX, and Home Depot; the client-side skimming and credential era of Magecart, British Airways, and the 2024 Snowflake campaign; and the identity and social engineering era defined by the 2025 Scattered Spider attacks on Marks and Spencer, Co-op, and Harrods.
The list below ranks incidents primarily by records affected, while keeping high-notability breaches that mattered more for their legal aftermath than their raw counts. Figures that are disputed, estimated, attacker-claimed, or sourced from Have I Been Pwned rather than the breached company are flagged inline, and scraping incidents are distinguished from genuine database exfiltration so you can tell a headline number from a verified one.
Every incident below sits on top of the same regulatory and cost baseline, and that baseline shifted hard in 2024 and 2025. Payment security rules now reach into the customer's browser, privacy regulators on three continents have started fining retailers at scale, and the sector's breach economics run against the wider market. Understanding this context is what separates reading a breach list from acting on it.
The Payment Card Industry Data Security Standard (PCI DSS) v4.0, published in March 2022, was the largest rewrite of the standard since its first release. It introduced a customized approach that lets an entity meet a security objective through its own validated controls, expanded multi-factor authentication to all access into the cardholder data environment, and added new client-side requirements aimed at web skimming. Version 4.0.1 followed in June 2024 as an errata and clarification revision that added no new requirements, and v4.0 was retired on December 31, 2024, leaving v4.0.1 as the only active version from January 1, 2025. The compliance burden date that matters is March 31, 2025, when a large tranche of future-dated requirements became mandatory in every assessment with no grace period. Sources cite 51, 53, or 64 future-dated requirements depending on how service-provider-only and multi-part items are counted, so the defensible fact to anchor on is the March 31, 2025 deadline itself, which is not in dispute. You can read the PCI Security Standards Council guidance on the e-commerce requirements for the official position.
Two of those future-dated requirements exist specifically to counter payment-page skimming, and they carry the heaviest practical load for online retailers. Requirement 6.4.3 requires that every script loaded and executed on the payment page in the consumer's browser is inventoried, justified in writing, authorized, and integrity-checked, and because tag managers, analytics vendors, and chat widgets push updates constantly, the inventory has to be maintained continuously rather than once. Requirement 11.6.1 requires a change-and-tamper detection mechanism that alerts staff to unauthorized modification of the payment page and its HTTP headers as received by the browser, evaluated at least weekly or at a frequency justified by a targeted risk analysis. Both requirements exist because Magecart-style attacks never touch the merchant's servers in a way that traditional server-side monitoring can see.
Magecart is the umbrella name for dozens of threat groups that inject JavaScript card skimmers into e-commerce checkout pages, a technique that dates to at least 2015. Two variants dominate: direct compromise of the merchant's own site, often through an unpatched platform such as an older Magento installation, and supply chain compromise of a third-party script provider, which lets a single injection reach thousands of stores at once. The Volusion compromise of 2019 affected roughly 6,500 merchant stores by researcher estimates, and the pattern is best understood as breadth rather than depth, with tens of thousands of compromised stores active at any moment across the past decade.
The two most consequential single victims came from the same year. British Airways had card and personal data skimmed from its site in 2018, and the UK Information Commissioner's Office (ICO) ultimately fined the airline £20 million, with the ICO British Airways penalty notice placing the potentially affected population in the range of roughly 380,000 to 429,000 people. Ticketmaster UK was skimmed in 2018 through a compromised Inbenta chatbot script and drew a £1.25 million ICO fine issued in November 2020. The class matters for retail specifically because the attack surface is the checkout page, which only e-commerce operates at scale.
Retailers that process European personal data face administrative fines under the General Data Protection Regulation (GDPR) of up to €20 million or 4% of global annual turnover, whichever is higher, along with 72-hour breach notification duties. Beyond the British Airways fine, the ICO fined Marriott £18.4 million in October 2020 over the Starwood breach.
In France the data protection regulator has been the most aggressive against retail. The CNIL fined the Irish entity of the SHEIN group €150 million on September 1, 2025 for depositing advertising cookies without consent. That penalty is an ePrivacy cookie enforcement action against Infinite Styles Services Co. Limited under the French Data Protection Act, not a data breach fine, and it should not be confused with SHEIN's 2018 Zoetop breach covered later in this list.
In the United States, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act, gives consumers a private right of action for breaches of unencrypted personal information with statutory damages of $100 to $750 per consumer per incident, which is the single largest driver of US retail breach class actions because it removes the need to prove individual harm. Enforcement is escalating: the California Privacy Protection Agency fined the clothing retailer Todd Snyder $345,178 in May 2025 over a broken opt-out mechanism and over-collection of identity documents. The California Attorney General's $1.2 million Sephora settlement in August 2022 remains the template retail enforcement action, and our overview of how to prevent data breaches covers the controls regulators now expect.
The retail threat picture increasingly runs through suppliers, and the numbers reflect it. The Verizon 2026 Data Breach Investigations Report counts 806 confirmed breaches in the retail vertical, and while its report-wide findings that vulnerability exploitation reached 31% of breaches, third-party involvement rose to about 48%, and the human element featured in 62% span all sectors rather than retail alone, the third-party figure is the most retail-relevant given how much recent retail breach history runs through vendors and cloud platforms. You can review the Verizon DBIR for the full dataset.
On cost, the IBM Cost of a Data Breach Report 2025 put the global average at $4.44 million, the first year-over-year decline in five years, and its industry breakdown placed the retail sector average at $3.54 million, well below healthcare at $7.42 million and financial services at $5.56 million. Retail was one of a small group of sectors that saw breach cost rise year over year even as most declined, and its below-average absolute cost reflects lower regulated per-record value rather than lower breach frequency.
The incidents below are ranked primarily by records affected, with disputed and attacker-claimed figures flagged where they appear. Read the flags carefully, because several of the largest headline numbers describe scraped data points or attacker listings rather than confirmed customer records. For cross-sector context beyond retail, see our wider roundup of the biggest data breaches.
A developer and his employer ran a crawler against Alibaba's Taobao shopping site, collecting user IDs, phone numbers, and comments before Alibaba detected the activity and reported it to police, and both men received suspended three-year sentences. The incident is routinely cited as one of the largest exposures in history, but nothing was stolen from a database and the scraped fields were data the platform itself displayed. It matters because it shows that for marketplaces, the exposure surface is defined by what the platform publishes at scale, not only by what it stores.
Aftermath: Criminal convictions in China with suspended sentences, and no regulatory fine against Alibaba for this incident.
Source: Reuters coverage of the Taobao scraping case
ShinyHunters listed a Ticketmaster dataset for sale, published samples, and later leaked barcode data for high-profile tours to pressure Live Nation, which confirmed unauthorized activity in a third-party cloud database environment. The failure was not in Ticketmaster's own perimeter but in single-factor authentication on a cloud data warehouse tenant, which makes it the defining example of consumer-facing third-party software risk.
Aftermath: US class actions were consolidated in the Central District of California, Australia's privacy regulator and others opened inquiries, and the Department of Justice charged alleged Snowflake-campaign actors Connor Moucka and John Binns in November 2024, with Moucka arrested in Canada.
Source: Live Nation SEC Form 8-K | Mandiant analysis of UNC5537
Attackers took a customer database of 153 million records plus source code for several products. Adobe encrypted passwords with 3DES in ECB mode using a single key rather than salting and hashing them, so identical passwords produced identical ciphertext, and the plaintext hints stored alongside let researchers reconstruct enormous numbers of passwords. Credential reuse from this dump fueled account takeover across the wider e-commerce ecosystem for years.
Aftermath: Adobe paid $1.1 million in legal fees and an undisclosed amount to consumers to settle claims from 15 state attorneys general, plus a separate class action settlement.
Source: Krebs on Security on the Adobe breach | Have I Been Pwned, Adobe
Under Armour disclosed that an unauthorized party acquired data tied to roughly 150 million accounts, at the time one of the largest single-application breaches ever reported. The disclosure was praised for speed, coming four days after discovery, but criticized for the inconsistent hashing that left the SHA-1 subset trivially crackable. The dataset later circulated on dark web markets.
Aftermath: Under Armour's share price fell on disclosure, and the company compelled arbitration under its terms of service, which limited its exposure. No major regulatory fine was reported.
Source: Reuters on the MyFitnessPal breach
Attackers used stolen employee credentials to move into eBay's network and copy a database covering all 145 million active accounts, and eBay asked every user to reset their password. The handling drew criticism because eBay took a fortnight to notify after discovery and the reset prompt was slow to reach many users. It stands as the largest pure marketplace account compromise of its era and an early sign that credential theft against employees, not payment terminals, would become the dominant retail attack path.
Aftermath: Investigations by three state attorneys general, the ICO, and the Luxembourg data protection authority followed, but no material fine was imposed, which is often cited as an example of pre-GDPR regulatory weakness.
Source: BBC coverage of the eBay breach
TJX ran WEP long after the industry had moved to stronger encryption and stored full track data against PCI rules, and Gonzalez's crew sat inside the network for a year and a half. For nearly seven years it was the largest retail breach on record, and it is the reason PCI DSS compliance became a board-level topic and directly informed card-data retention prohibitions.
Aftermath: TJX booked charges of roughly $256 million, settled with Visa issuers for up to $40.9 million and Mastercard issuers for up to $24 million, paid roughly $9.75 million to 41 state attorneys general, and settled a consumer class action. Gonzalez was sentenced to 20 years in federal prison in 2010.
Source: US Department of Justice on the Gonzalez sentencing | Wired on the TJX wireless hack
Everest listed Under Armour on its leak site in November 2025 and, after extortion failed, published the dataset to a cybercrime forum, which Troy Hunt loaded into Have I Been Pwned three days later. That notification reached roughly 72 million subscribers before the company confirmed anything, a pattern that became routine in 2025 and 2026. It is the second nine-figure-scale exposure associated with Under Armour after MyFitnessPal.
Aftermath: Under Armour said it was investigating and reported no evidence of password or payment compromise, with US class action filings following in the first quarter of 2026 and regulatory outcomes still pending as of August 2026.
Source: Have I Been Pwned, Under Armour | TechCrunch on the Under Armour breach claims
Target's FireEye deployment generated alerts during the intrusion and its Bangalore security team escalated them, but the alerts were not acted on in Minneapolis, which made Target the canonical case study in why detection without response is worthless. The breach became the single most important driver of the US migration to EMV chip cards and made third-party vendor access a mainstream board-level risk.
Aftermath: CEO Gregg Steinhafel and CIO Beth Jacob both departed, and Target reported gross breach costs of roughly $292 million. Settlements included $39 million to banks and credit unions, $67 million to Visa issuers, an $18.5 million multistate settlement with 47 state attorneys general and the District of Columbia in May 2017, then the largest of its kind, and a $10 million consumer class settlement.
Source: California Attorney General on the $18.5 million Target settlement | Krebs on Security on the Target HVAC vector
"Satanic" tried to sell the data on BreachForums for $20,000 and separately tried to extort $100,000 from Hot Topic, which did not issue a substantive public statement, so Have I Been Pwned again became the effective notification channel. It stands as one of the largest US retail breaches by raw account count and another case where a mid-tier analytics vendor, not the retailer, was the entry point.
Aftermath: Class actions were filed in federal court, and Hot Topic's silence drew criticism likely to feature in state attorney general scrutiny.
Source: BleepingComputer on the Hot Topic notification | Have I Been Pwned
The malware ran undetected on self-checkout systems for roughly five months, making it larger than Target by card count, and later reporting described an under-resourced security program running outdated antivirus. Home Depot accelerated its rollout of EMV chip-and-PIN terminals and point-to-point encryption, reinforcing the lesson that unchecked third-party access plus flat internal networks equals estate-wide POS compromise.
Aftermath: Home Depot reported gross breach costs of roughly $298 million before insurance, paid a $19.5 million consumer class settlement, $25 million to financial institutions, roughly $27.25 million to Visa and Mastercard issuers, and a $17.5 million multistate settlement with 46 state attorneys general and the District of Columbia in November 2020.
Source: California Attorney General on the $17.5 million Home Depot settlement | Krebs on Security on the Home Depot breach
Zoetop, then the parent of both brands, learned of the breach in 2018 but contacted only a fraction of affected users, and the New York Attorney General found that more than 32.5 million accounts were never told their credentials had been stolen while the company misrepresented the scope publicly. This is the most instructive retail case on breach response conduct rather than breach cause, because the penalty was driven almost entirely by what the company said and failed to say afterward.
Aftermath: A $1.9 million settlement with the New York Attorney General in October 2022, plus injunctive terms on security, password hashing, and incident response. Separately, and unrelated to this breach, the CNIL fined SHEIN's Irish entity €150 million in September 2025 over cookie consent.
Source: New York Attorney General on the Zoetop settlement | CNIL on the SHEIN cookie fine
Houlihan reported the flaw to Panera's then-CIO in August 2017 and was accused of running a scam, and Panera took no effective action for eight months. When Krebs published, Panera briefly took the site down and told reporters the issue was resolved, while researchers showed the endpoint was still leaking. It remains the definitive retail case study in mishandled vulnerability disclosure, and the flaw class, broken object level authorization, still tops the OWASP API Security Top 10.
Aftermath: Reputational damage and sustained criticism rather than regulatory penalty, with no significant fine reported.
Source: Krebs on Security on the Panera leak
Access persisted for roughly five months before detection, and the first public estimate of 4,500 affected individuals was revised to more than 33 million within days, which became a major part of the scandal in Korea. As the country's largest online retailer, the breach touched a majority of the adult population, making it the largest consumer data breach in South Korean history.
Aftermath: Coupang announced compensation vouchers worth 50,000 won per affected customer, a program valued at roughly $1.17 billion, and on June 11, 2026, the Personal Information Protection Commission imposed a record fine of 624.9 billion won, roughly $409 million at the time, the largest privacy penalty in South Korean history.
Source: SecurityWeek on the Coupang voucher program | Cybernews on the Coupang breach
Neiman Marcus is a rare retailer that appears in both the POS malware era and the cloud third-party era, which makes it a useful bookend. In 2024 it was caught in the same Snowflake campaign as Ticketmaster and Advance Auto Parts, and the order-of-magnitude gap between the 64,472 people it notified and the 31 million email addresses found in the dump is one of the clearest illustrations of how legal notification thresholds and actual exposure diverge.
Aftermath: 2013: a $1.6 million settlement with 43 state attorneys general and the District of Columbia in January 2019, plus a $1.5 million consumer class settlement. 2024: class actions filed in the Northern District of Texas, since settled.
Source: BleepingComputer on the Neiman Marcus Snowflake breach | BleepingComputer on 31 million exposed email addresses
Malware sat on Wawa's payment servers for roughly nine months across the entire estate, and in January 2020 the Joker's Stash marketplace began uploading the trove, which is how the scale became public. It is one of the last very large POS malware breaches in the United States, exploiting the extended EMV deadline that left fuel dispensers processing magnetic stripe transactions.
Aftermath: An $8 million multistate settlement co-led by New Jersey and Pennsylvania in July 2022, plus a consumer class settlement valued at up to $9 million and a separate settlement with financial institutions.
Source: New Jersey Attorney General on the Wawa settlement | Krebs on Security on the Wawa breach
Attackers ran malware across more than 5,000 tills for nine months, and the ICO's investigation under the pre-GDPR Data Protection Act 1998 found systemic failures in basic hygiene. It is the largest UK retail POS compromise on record, and the pre-GDPR legal basis capped the penalty at £500,000, a figure the ICO explicitly noted was the maximum available.
Aftermath: A £500,000 ICO fine in January 2020, the maximum permitted under the Data Protection Act 1998. Dixons Carphone contested the penalty through a multi-year appeal: the First-tier Tribunal reduced it to £250,000 in 2022 and the Upper Tribunal later sided with the company, before the ICO won at the Court of Appeal in February 2026. The company was renamed Currys plc.
Source: ICO on the DSG Retail Court of Appeal ruling
JD Sports disclosed that a server containing two years of legacy order history had been accessed, and the most notable feature is the data retention question, because the records were between two and four years old at the time of the breach. It is a useful entry precisely because there is no exotic technique to distract from the governance failure of retaining accessible order data for 10 million customers.
Aftermath: The ICO was notified, and no public enforcement action had been reported as of August 2026.
Source: BBC on the JD Sports breach
Co-op detected the intrusion and took systems offline pre-emptively, which limited the damage relative to Marks and Spencer but caused significant logistics disruption, including empty shelves in remote communities where it is the only grocer. The CEO's early public apology and willingness to confirm the full figure stand in contrast to the disclosure practice of several other retailers caught in the same wave of UK data breaches.
Aftermath: Co-op assessed revenue losses of roughly £206 million and a profit impact of around £80 million. The Cyber Monitoring Centre classified the Marks and Spencer and Co-op incidents together as a single combined event with an estimated UK economic impact of £270 million to £440 million. Four people were arrested by the National Crime Agency in July 2025 in connection with the attacks.
Source: Computer Weekly on the Co-op breach | National Crime Agency on the arrests
ShinyHunters gained access to Panera's corporate environment, exfiltrated data, demanded a ransom, and published the archive when Panera declined to pay, with Panera confirming that the data involved was contact information and that authorities had been notified. This is Panera's second major exposure after the 2018 API leak, and the two together illustrate how the retail threat model shifted from insecure web endpoints to identity provider abuse in under a decade.
Aftermath: US class actions were filed in early 2026, and the regulatory position was still developing as of August 2026.
Source: Fox News on the Panera breach | Have I Been Pwned, Panera Bread
FIN7 compromised the entire Lord and Taylor store network and 83 Saks Fifth Avenue locations for roughly ten months, then began selling the cards in tranches. It demonstrated that a decade after TJX, US specialty retail POS estates were still being harvested at scale by a professionalized criminal organization operating through the fake security company Combi Security.
Aftermath: Class actions in the US and Canada, and several FIN7 leaders were convicted, including Fedir Hladyr, sentenced to 10 years in 2021.
Source: Gemini Advisory on the FIN7 Saks and Lord and Taylor hack | US Department of Justice on the FIN7 sentencing
This was the most consequential retail cyber incident in the United Kingdom in a decade. Marks and Spencer suspended online ordering for roughly six weeks, saw contactless payment and click-and-collect fail in stores, and reverted parts of its food supply chain to manual processes. The attack path was mundane, a help desk password reset for a plausible-sounding caller, and that is precisely why it reset the sector's understanding of identity and outsourcing risk.
Aftermath: The roughly £300 million figure is the guided hit to 2025/26 group operating profit before mitigation, not the net or final cost. The company signalled it expected to roughly halve that through cost actions and an insurance claim of up to about £100 million. The Cyber Monitoring Centre classified the Marks and Spencer and Co-op attacks together as a single event with an estimated UK economic impact of £270 million to £440 million. Four people were arrested by the National Crime Agency in July 2025, and the company gave evidence to the House of Commons Business and Trade Committee.
Source: TechCrunch on the Marks and Spencer breach | BleepingComputer on the Scattered Spider link
Harrods is the clearest demonstration that containment works. In May 2025 it detected intrusion attempts and restricted internet access across its sites, reporting no data compromise, in contrast to Marks and Spencer's lost six weeks of trading. Four months later it was caught anyway through a supplier, which separates the two failure modes neatly: your own identity perimeter, and everyone you have handed customer data to.
Aftermath: Harrods described the September incident as isolated and contained, said it would not engage with the attackers, and notified the ICO. Four people were arrested by the National Crime Agency in July 2025, and no fine had been reported as of August 2026.
Source: BleepingComputer on the Harrods breach | National Crime Agency on the arrests
Adidas disclosed that an unauthorized party obtained consumer contact data through a third-party customer service provider, weeks after reporting similar compromises affecting its Turkish and South Korean operations. That made the pattern the story rather than the single event, because one outsourced contact-centre relationship, replicated across regions, produced repeated exposure of the same data class.
Aftermath: Adidas notified regulators and law enforcement and began contacting affected consumers, with no fine reported as of August 2026 and the February 2026 claim unresolved.
Source: SecurityWeek on the Adidas vendor breach | The Register on the 2026 Adidas claim
Across 2025 a sequence of intrusions hit LVMH subsidiaries one after another, each through customer-facing data platforms operated with third parties. What makes the cluster important is the regulatory outcome rather than the record count, because South Korea's regulator treated the brands as having failed to implement adequate security and issued one of the few at-scale luxury retail breach fines, placing it among the most consequential European data breaches of the year. It also shows that clienteling data is a high-value target even without card numbers.
Aftermath: On February 12, 2026, South Korea's Personal Information Protection Commission imposed a total of 36.033 billion won, roughly $25 million, plus 10.8 million won in additional penalties, split across Louis Vuitton Korea, Christian Dior Couture Korea, and Tiffany Korea. Class actions were filed in Canada and the United States.
Source: BleepingComputer on the LVMH brand fines | BleepingComputer on Dior US notifications
Within days in September 2024, customer databases from Boulanger, Cultura, and Truffaut appeared for sale and then for free on cybercrime forums, with further French retailers disclosing incidents in the following weeks. The cluster is the clearest European example of concentration risk in retail logistics, and it stands out among recent French data breaches because several competing chains handed delivery data to the same class of subcontractor, so a single supplier compromise produced a national-scale exposure.
Aftermath: The affected retailers notified the CNIL and their customers, and no fines specific to this cluster had been reported as of August 2026. The wave contributed directly to CNIL guidance on subcontractor security obligations under GDPR Article 28.
Source: The Record on the French retailer breaches | Cybernews on the Boulanger leak
Advance Auto Parts was one of roughly 165 organizations caught in the 2024 Snowflake campaign, and it is the most instructive retail victim precisely because the exposed data was employment-related. Retail HR and applicant-tracking data sits in the same analytics platforms as commercial data and carries Social Security numbers that shopper records do not, which raises the identity theft severity by an order of magnitude.
Aftermath: Twelve months of credit monitoring were offered, class actions were consolidated, and a settlement followed. The wider campaign led to US charges against Connor Moucka and John Binns.
Source: BleepingComputer on the Advance Auto Parts breach | Cybersecurity Dive on the Snowflake-linked attack
Pandabuy buys goods on Chinese marketplaces for overseas customers and reships them, so its database links a Western identity and home address to a full purchase history. The company's initial response through a Discord administrator, calling the data old and the issue handled, drew criticism, and the dataset was loaded into Have I Been Pwned. It is the cleanest recent example of an API-layer breach at a pure e-commerce intermediary and of a threat actor inflating a record count that was then repeated uncritically.
Aftermath: No regulatory action was publicly reported, the platform continued to operate, and reporting later described extortion attempts.
Source: BleepingComputer on the Pandabuy leak | Have I Been Pwned, Pandabuy
A threat actor posted what it described as a 61 GB Russell Cellular dataset for sale. As an authorized Verizon retailer rather than a carrier, its records mirror carrier account data without sitting behind carrier-grade security, and the affected customer generally has no idea the retailer exists as a separate data controller. As of the available reporting the company had not notified affected individuals, which drew class action investigation notices alleging notification delay.
Aftermath: Class action investigations were announced in April 2026, with no confirmed company statement, regulatory filing, or notification program reported as of August 2026.
Source: Cybernews on the Russell Cellular claim | Schubert Jonckheer and Kolbe investigation notice
Michaels sat in the middle of the 2013 to 2014 US POS malware wave alongside Target and Neiman Marcus, with the same disclosure pattern of a Krebs report, then a company acknowledgement, then a confirmed figure months later. It is worth including because the earlier 2011 PIN pad swap makes Michaels one of the few US retailers compromised twice by entirely different card theft techniques within three years, a reminder that fixing one card-data attack surface does not address the others.
Aftermath: Free credit monitoring was offered, and consumer class actions became part of the developing US case law on whether increased fraud risk alone confers standing. No major regulatory fine was reported.
Source: Krebs on Security on the Michaels breach | BankInfoSecurity on the Michaels confirmation
Dymocks is the canonical migration-window breach. Customer data was in motion between an old and a new loyalty provider, and the copies created for that migration were the copies that leaked, trading publicly for roughly three months before an external researcher told the company. For a mid-sized retailer it is a more realistic cautionary tale than the nine-figure incidents, and it ranks among the most cited Australian data breaches, because the failure required no sophistication, only a temporary dataset held by a supplier during a project.
Aftermath: Dymocks notified the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme and contacted affected customers, with no penalty reported as of August 2026.
Source: BleepingComputer on the Dymocks breach | ACS Information Age on the Dymocks hack
Forever 21 also suffered an earlier and separate card breach in 2017 involving POS malware, but the 2023 incident matters for a different reason: it is the sharpest example that a retailer's most sensitive data is usually its HR and benefits data, not its customer data. Half a million people had Social Security numbers, bank account numbers, and health plan details exposed by a clothing retailer, a combination that supports identity theft, financial fraud, and benefits fraud at once, and none of it was protected by PCI DSS because none of it was card data.
Aftermath: One year of credit monitoring was offered, multiple class actions were filed in federal court, and the five-month notification gap became a focus of the litigation.
Source: TechCrunch on the Forever 21 breach | HIPAA Journal on the Forever 21 breach
The three eras in this list point to the same conclusion: retail risk now spans a retailer's own attack surface, its vendor ecosystem, and its workforce at the same time, and treating those as separate problems is what lets a single help desk call or an unmonitored checkout script turn into an estate-wide incident. UpGuard is a cyber risk posture management platform that unifies all three surfaces so security teams can see and act on exposure in one place.
To see how this unified view applies to your own environment, you can start a free trial of the UpGuard platform.
By confirmed customer scale, Coupang's 2025 breach of 33.7 million accounts is the largest verified retail incident, while Ticketmaster's attacker-claimed 560 million and Alibaba's 1.1 billion scraped data points are larger headline numbers that the companies have not confirmed.
Most fall into three patterns: point-of-sale malware that scrapes card data in stores, client-side skimming or credential theft against checkouts and cloud platforms, and social engineering that tricks a help desk into resetting an employee's access.
In late 2013, attackers used credentials stolen from an HVAC contractor to reach Target's payment network and deploy malware that captured 40 million payment cards and personal data for up to 70 million customers.
Yes. Skimming groups continue to inject JavaScript into checkout pages and third-party scripts, which is why PCI DSS 4.0.1 now requires merchants to inventory payment-page scripts and detect tampering.
Scattered Spider is the threat cluster behind the 2025 attacks on Marks and Spencer, Co-op, and Harrods, which used help desk impersonation to reset credentials and bypass multi-factor authentication rather than any technical exploit.
Continuously monitor your external attack surface and payment pages, assess and monitor third-party suppliers and cloud tenants for weak authentication, and treat identity and help desk processes as a primary control by requiring strong verification before any credential reset.