H&M

Aug 2026 · Graded Attested · Retail and Consumer · Beyond the filings

Incident summary

H&MAug 2026
Not yet quantified
AAttested
H&M confirmed that an attack on a business system exposed Korean customers' email addresses, phone numbers, and order or return reference numbers. More sensitive payment and password data were reportedly not affected, but the company did not disclose the number of customers or the access path. The useful boundary held around payment data; disclosure and accountability around the breached business tool remain thin.
Retail and Consumer
H&M discloses customer data breach in South Korea
Initial attack type not disclosed · Impact data theft confirmed

About this record

This incident is beyond the filings: attributed to a company statement, a regulator or court record, or a news report, and graded Attested or Inferred. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.

Cite this incident

← The complete Beyond the Filings ledger ← Back to the index