Breach Intelligence Report 06 Apr 2025

524,413 A.P.C. Customer Records Breached: Names, Emails, Phone Numbers Leaked

HEROIC
HEROIC Threat Intelligence Team
Email Address Phone Number First Name Last
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 524,413
Source Type Database
Origin Darkweb
Password Type No Passwords

On November 16, 2024, a database belonging to A.P.C. (Atelier de Production et de Creation), the French fashion brand founded by Jean Touitou, was compromised. The breach affected apc-us.com, the brand's US-facing domain, and exposed the records of 524,413 customers. The leaked data was identified through routine monitoring of dark web forums, where a structured dataset containing core contact and identity fields was circulating. No passwords were included, but the volume and specificity of the personal information make this a meaningful exposure.


Why This Is Dangerous

A dataset of over half a million email and phone combinations tied to real full names is exactly what attackers use to run phishing campaigns at scale. Because A.P.C. customers are identifiable as affluent fashion consumers, the data has elevated value for spear-phishing and financial fraud. Attackers can craft convincing emails that reference the brand by name, dramatically improving click-through rates. The phone numbers add a second channel for smishing and voice-based social engineering.


What Was Exposed

  • Email addresses linked to A.P.C. US customer accounts
  • Phone numbers associated with those accounts
  • First names and last names of 524,413 customers
  • Breach type: Database exfiltration via access control failure or misconfiguration
  • Affected domain: apc-us.com (US customer base)
  • Date leaked: November 16, 2024

Why This Matters

The combination of full name, email, and phone number is the trifecta attackers need to move from reconnaissance to action:

  • Credential stuffing: Email addresses are tested against passwords from other breaches across streaming, banking, and retail platforms.
  • Account takeover: Full names and emails allow attackers to pass security questions and identity verification steps on many services.
  • Identity theft: A verified name-email-phone combination is enough to open accounts or apply for credit in a victim's name in some jurisdictions.
  • Targeted fraud: Brand-specific phishing emails referencing A.P.C. purchases or loyalty programs are far more convincing than generic scams.

How Database Breaches Work

Database breaches at retail and fashion brands typically occur through one of three vectors: misconfigured cloud storage buckets that leave databases publicly accessible, SQL injection vulnerabilities in web application layers, or compromised administrative credentials. Once access is gained, extracting hundreds of thousands of records takes only minutes. The structured nature of the A.P.C. dataset suggests a direct database dump rather than a scraping attack, pointing to a deeper infrastructure compromise.


Check If You Are Affected

If you have ever shopped at A.P.C.'s US website or created an account at apc-us.com, your information may be part of this breach. Heroic indexes over 400 billion leaked records, giving you one of the most complete views available of where your data has appeared online. Search your email address now to find out.

Search the Heroic 400B+ database now and find out if your A.P.C. account data was exposed.

Breach Breakdown

Domain N/A
Leaked Data Email Address, Phone Number, First Name, Last Name
Password Types No Passwords
Date Leaked 06 Apr 2025
Check in 5 seconds

524,413 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,010 scanned today
Breach Rank #2,012 by affected users
Impact Score
21
sensitivity + scale + recency
Est. Financial Impact $3.8M fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance