Cyber Incident Victim: Herff Jones
Date:
May 2021
Location:
United States of America
Summary
A data breach at Herff Jones, a vendor providing graduation cap and gown services to a university, compromised students’ banking information, including debit card details. Multiple students reported unauthorized access to their financial data, with one individual confirming bank notifications about compromised card information but no funds withdrawn. The vendor had not publicly acknowledged the incident or provided details on its website at the time of reporting, prompting external inquiries into the breach’s scope and origin.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
In May 2021, a data breach at Herff Jones, a vendor supplying graduation caps and gowns to the University of Houston, compromised students' banking information. The incident came to light when Mariah Ochoa, a psychology senior, publicly disclosed on Twitter that her debit card information had been stolen on May 9, 2021. Ochoa reported receiving direct communication from her bank alerting her to the compromise, though no unauthorized transactions had occurred on her account at that time. She had placed her order with Herff Jones in February or March 2021 through the company's standard purchasing process. Multiple University of Houston students responded to Ochoa's social media post with similar accounts of their payment card information being compromised, indicating a broader pattern of unauthorized access to financial data tied to Herff Jones transactions.

The breach directly exposed sensitive payment card details used by students to purchase graduation attire through Herff Jones' systems. While no fraudulent withdrawals or charges were confirmed in Ochoa's case, the compromise necessitated bank-level security interventions to prevent financial loss. As of May 10, 2021, Herff Jones had not published any official notice about the incident on its corporate website or through other public channels. DataBreaches.net initiated contact with the company seeking details regarding the breach's scope, root cause, and affected population but received no immediate response. The lack of public acknowledgment by Herff Jones left students without direct guidance from the vendor regarding potential risks or protective measures related to the data exposure.
