524,413 A.P.C. Customer Records Breached: Names, Emails, Phone Numbers Leaked
On November 16, 2024, a database belonging to A.P.C. (Atelier de Production et de Creation), the French fashion brand founded by Jean Touitou, was compromised. The breach affected apc-us.com, the brand's US-facing domain, and exposed the records of 524,413 customers. The leaked data was identified through routine monitoring of dark web forums, where a structured dataset containing core contact and identity fields was circulating. No passwords were included, but the volume and specificity of the personal information make this a meaningful exposure.
Why This Is Dangerous
A dataset of over half a million email and phone combinations tied to real full names is exactly what attackers use to run phishing campaigns at scale. Because A.P.C. customers are identifiable as affluent fashion consumers, the data has elevated value for spear-phishing and financial fraud. Attackers can craft convincing emails that reference the brand by name, dramatically improving click-through rates. The phone numbers add a second channel for smishing and voice-based social engineering.
What Was Exposed
- Email addresses linked to A.P.C. US customer accounts
- Phone numbers associated with those accounts
- First names and last names of 524,413 customers
- Breach type: Database exfiltration via access control failure or misconfiguration
- Affected domain: apc-us.com (US customer base)
- Date leaked: November 16, 2024
Why This Matters
The combination of full name, email, and phone number is the trifecta attackers need to move from reconnaissance to action:
- Credential stuffing: Email addresses are tested against passwords from other breaches across streaming, banking, and retail platforms.
- Account takeover: Full names and emails allow attackers to pass security questions and identity verification steps on many services.
- Identity theft: A verified name-email-phone combination is enough to open accounts or apply for credit in a victim's name in some jurisdictions.
- Targeted fraud: Brand-specific phishing emails referencing A.P.C. purchases or loyalty programs are far more convincing than generic scams.
How Database Breaches Work
Database breaches at retail and fashion brands typically occur through one of three vectors: misconfigured cloud storage buckets that leave databases publicly accessible, SQL injection vulnerabilities in web application layers, or compromised administrative credentials. Once access is gained, extracting hundreds of thousands of records takes only minutes. The structured nature of the A.P.C. dataset suggests a direct database dump rather than a scraping attack, pointing to a deeper infrastructure compromise.
Check If You Are Affected
If you have ever shopped at A.P.C.'s US website or created an account at apc-us.com, your information may be part of this breach. Heroic indexes over 400 billion leaked records, giving you one of the most complete views available of where your data has appeared online. Search your email address now to find out.
Search the Heroic 400B+ database now and find out if your A.P.C. account data was exposed.
Breach Breakdown
524,413 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds