Official Case FileTX · Jan 23, 2026

FullBeauty Brands, Inc. Data Security Incident

Investigation Open

Reported to the TX Attorney General on January 23, 2026.

TX residents may qualify for compensation. Free attorney review — no obligation, no upfront cost.

Check My Rights →
§ I

Incident Overview

FullBeauty Brands, Inc. was the subject of a data breach notification filed with the TX Attorney General. The AG filing was recorded on January 23, 2026. The breach or discovery date reported in the filing is October 18, 2025.

FullBeauty Brands, Inc. operates as a prominent digital and catalog-based apparel retailer specializing in plus-size clothing, footwear, and lifestyle products, serving a massive, dedicated consumer base across the United States. Because of its direct-to-consumer e-commerce model, the company maintains extensive digital infrastructure that collects, processes, and stores vast quantities of personally identifiable information. This repository routinely includes customer names, billing and shipping addresses, telephone numbers, email credentials, detailed transaction histories, and sensitive financial data such as credit or debit card numbers associated with online purchases. The sheer volume of transactions processed daily makes FullBeauty Brands a prime target for malicious cyber actors seeking to monetize consumer data on the illicit dark web. In 2026, FullBeauty Brands, Inc. formally reported a significant security incident to the Texas Attorney General, triggering legal scrutiny regarding the adequacy of its digital safeguards. While breach notifications often attribute such events to sophisticated external threats, third-party vendor compromises, or unauthorized network intrusions, the underlying reality for major e-commerce platforms typically involves vulnerabilities within payment gateways, customer database access controls, or outdated security patches. In the retail sector, attackers frequently deploy credential-stuffing tools, malware, or ransomware to infiltrate central databases where customer profiles and transactional histories are consolidated, allowing unauthorized access to persist undetected for extended periods. The exposure of retail and e-commerce data creates severe, multi-faceted risks for affected consumers. When databases containing customer names, physical addresses, email addresses, and payment card details are compromised, victims face an immediate threat of financial fraud, unauthorized credit card charges, and phishing attacks tailored to their purchasing habits. Furthermore, the combination of personal identifiers and transaction history enables threat actors to execute sophisticated identity theft schemes, opening fraudulent lines of credit or hijacking existing accounts. Unlike fleeting inconveniences, the compromise of immutable personal data leaves victims vulnerable to ongoing exploitation for years after the initial incident. As a commercial entity operating within interstate commerce and collecting consumer data in Texas, FullBeauty Brands, Inc. was legally obligated to implement reasonable security measures to protect sensitive customer information. Under state consumer protection statutes, including the Texas Business and Commerce Code, and Section 5 of the Federal Trade Commission Act, companies that gather payment and personal details have an affirmative duty to maintain robust administrative, technical, and physical safeguards. A successful breach of this magnitude strongly indicates a failure to maintain adequate encryption, timely vulnerability patching, or rigorous access controls, which constitutes a breach of the implied contract between the consumer and the retailer. Receiving an official data breach notification letter from FullBeauty Brands, Inc. serves as formal legal admission that your private information was compromised due to inadequate corporate security. Under modern legal standards, the receipt of such a notice establishes concrete legal standing to participate in a class action lawsuit, even before fraudulent charges appear on your financial statements. Courts increasingly recognize that the mitigation efforts, anxiety, and imminent risk of identity theft resulting from a corporate data breach constitute actionable harm. Our firm is actively investigating potential legal claims on behalf of affected consumers, operating strictly on a contingency fee basis—meaning you pay nothing out of pocket, and we only recover fees if we successfully secure a recovery on your behalf.
§ II

Case Facts & Filing Record

State Filed
TX
Date Reported to AG
Jan 23, 2026
Date of Breach
Oct 18, 2025
Records Affected
Not disclosed
Filing Status
Investigation Open
Last Updated
Oct 5, 2026
Data Types Exposed
Full NameMailing AddressEmail AddressPhone NumberPurchase and Order HistoryPayment Card InformationPassword or Credential Hash
§ III

Risk Analysis — Exposed Data

Based on the data types reported in this filing, affected individuals face the following specific risks:

SIM Swap & Vishingmedium

Phone numbers exposed in breaches are used for SIM swapping attacks — hijacking your number to bypass two-factor authentication on financial accounts.

§ IV

Who Was Impacted?

Under the Texas Identity Theft Enforcement and Protection Act, you may have a legal claim against FullBeauty Brands, Inc. if any of the following apply:

  • You received a written data breach notification letter from FullBeauty Brands, Inc.
  • You are or were a customer, patient, or employee of FullBeauty Brands, Inc.
  • Your information was held by FullBeauty Brands, Inc. in TX

Applicable law: This breach was reported under the Texas Identity Theft Enforcement and Protection Act, which establishes your right to seek damages from FullBeauty Brands, Inc..

§ V

What the Law Gives You — Compensation Available

01
Lost Time & Remediation Costs

The hours spent responding to a data breach — canceling accounts, contacting credit bureaus, updating passwords, and investigating fraud — represent compensable economic harm in data breach litigation.

02
Account Compromise Damages

When login credentials are exposed, the costs of downstream account compromises — password managers, security audits, and recovery costs for hijacked downstream accounts — can be recovered. Courts in recent class actions have awarded damages for credential exposure even without proven misuse.

03
Emotional Distress

Data breach victims regularly report anxiety, loss of sleep, and ongoing fear of identity theft. These non-economic harms are cognizable injuries in data breach litigation, particularly in cases involving SSN or medical record exposure.

Note: an attorney general breach filing does not by itself establish a settlement fund, a payment amount, or a claim deadline. If an official settlement notice is later issued, rely on that notice for payment details and deadlines.

§ VI

Frequently Asked Questions

Do I need proof that my data was misused to file a claim against FullBeauty Brands, Inc.?

No. Under Texas Identity Theft Enforcement and Protection Act and federal law, the unauthorized exposure of your personal data — regardless of whether it has been actively misused — can be sufficient grounds for a claim. The breach itself is the injury.

How much does filing a claim cost?

Nothing. The Law Office of David S. Harris handles data breach cases on contingency — you pay zero upfront and owe nothing unless compensation is recovered.

Is there a deadline to file a claim?

State statutes of limitations for data breach claims typically run 2–4 years from the date of the breach or its discovery. Because this breach was recently disclosed, the window is open — but acting early preserves your options and strengthens the case.

What if FullBeauty Brands, Inc. offered me free credit monitoring after the breach?

Accepting free credit monitoring from FullBeauty Brands, Inc. does not waive your right to pursue legal action unless you signed a specific release waiving claims. In most cases, victims who accepted monitoring can still file.

Do I need to have received a notice letter to be eligible?

Not necessarily. Many data breach victims are never notified directly. If your personal information was held by FullBeauty Brands, Inc. during the relevant period, you may still qualify even without receiving a letter. A free eligibility review can confirm your status.

How long does a data breach class action lawsuit take?

Most data breach class actions resolve within 18 to 36 months, though timelines vary by court and complexity. Your participation requires minimal effort — typically completing a claim form. Our office handles all litigation; you are notified when a settlement is reached.

Received a notification letter from FullBeauty Brands, Inc.?

Read our dedicated guide — what the letter means and exactly what to do.

Read Letter Guide →
§ VII

Submit Your Free Case Review

If you were affected by the FullBeauty Brands, Inc. data breach, you may be entitled to compensation. Submit your information below for a free attorney review — no obligation, no upfront cost.

Tell Us About Your Notice Letter

Received a data breach notification letter? Fill out the form — an attorney will review your mailing and contact you. No cost, no obligation.

Start typing to find a matching case, or enter a company not yet listed.

Attach a copy of your data breach notification letter. Accepted: PDF, JPG, PNG — max 10 MB.

No attorney-client relationship is created by submitting this form. Attorney Advertising.

Source: State Attorney General filing, TX

View Official AG Filing →

FullBeauty Brands, Inc. breach?

Free case review · No fee unless you win

Call Now