H&M

Aug 2026 · Graded Attested · Retail and Consumer · Beyond the filings
H&MAug 2026
H&M confirmed that an attack on a business system exposed Korean customers' email addresses, phone numbers, and order or return reference numbers. More sensitive payment and password data were reportedly not affected, but the company did not disclose the number of customers or the access path. The useful boundary held around payment data; disclosure and accountability around the breached business tool remain thin.
H&M discloses customer data breach in South Korea
Not yet quantified
AAttestedRetail and Consumer
About this record
This incident is beyond the filings: attributed to a company statement, a regulator or court record, or a news report, and graded Attested or Inferred. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.
← The complete Beyond the Filings ledger ← Back to the index