2019 Fossil Group — e-commerce payment-card data incident (Misfit.com and related storefronts)
Data compromised
Payment-card information and related customer order fields described in state breach summaries; full population counts varied by filing
Technical writeup
Fossil Group notified U.S. state regulators and consumers that unauthorized actors accessed payment-card data on certain e-commerce checkouts—including Misfit.com—during a mid-2019 window, prompting site downtime, forensic remediation, and multistate breach filings. Retail security press summarized the case as a payment-data exposure rather than a full ERP compromise, while the company’s subsequent Form 10-K discussed material litigation and regulatory risk flowing from the event.
Root cause
Criminal access to card data processed through affected e-commerce properties (unauthorized network/code or checkout-path intrusion characterized in AG notices)