Comparison Overview

American Eagle Outfitters Inc.

VS

Toys"R"Us

American Eagle Outfitters Inc.

77 Hot Metal Street, Pittsburgh, 15203, US
Last Update: 2025-12-17
Between 750 and 799

American Eagle Outfitters (AEO) is a portfolio of unique, loved and enduring brands: American Eagle, Aerie, OFFL/NE by Aerie, Todd Snyder and Unsubscribed. We provide a welcoming and engaging customer and associate experience, and we embrace all. Merchandise assortments consist of high-quality, on-trend apparel, intimates, activewear, accessories, and personal care products for women and men. We are a true omni-channel retailer with a global reach. Our brands are connected under the core tenet of REAL, which is optimistic, empowering and celebrates individual self-expression. That power and authenticity drives us to create a positive impact across every facet of our business, brands, and products. We are a company led by purpose. Over ten years ago, we introduced AEO Better World – an initiative grounded in social responsibility and giving back to our communities. Across our brands, we support a number of important causes that are meaningful to our customers and associates. We operate with integrity and a strong set of values, which is ingrained across our business and in how we treat our associates, business partners and customers. At AEO, we believe that our associates are our most valuable asset and we want them to feel motivated and have the freedom to be themselves at work. We strive to be an employer of choice – a place where people are excited to come to work because they believe in what we do, enjoy working with each other and have fun doing it. If you think AEO sounds like a fun place to work and grow your career, you’re right!

NAICS: 43
NAICS Definition: Retail Trade
Employees: 22,006
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

Toys"R"Us

Parsippany, New Jersey, US, 07054
Last Update: 2025-12-17
Between 750 and 799

Toys“R”Us is a beloved brand known all around the world—and we know how to have fun! For over 70 years we've been the toy authority and ambassadors of all things play. Our new vision looks beyond traditional retail for a re-imagined, immersive experience for kids of all ages. We've got a whole new way to play, and we can't wait to share it with you!

NAICS: 43
NAICS Definition: Retail Trade
Employees: 13,539
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/american-eagle-outfitters.jpeg
American Eagle Outfitters Inc.
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/toysrus1.jpeg
Toys"R"Us
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
American Eagle Outfitters Inc.
100%
Compliance Rate
0/4 Standards Verified
Toys"R"Us
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Retail Industry Average (This Year)

No incidents recorded for American Eagle Outfitters Inc. in 2025.

Incidents vs Retail Industry Average (This Year)

No incidents recorded for Toys"R"Us in 2025.

Incident History — American Eagle Outfitters Inc. (X = Date, Y = Severity)

American Eagle Outfitters Inc. cyber incidents detection timeline including parent company and subsidiaries

Incident History — Toys"R"Us (X = Date, Y = Severity)

Toys"R"Us cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/american-eagle-outfitters.jpeg
American Eagle Outfitters Inc.
Incidents

No Incident

https://images.rankiteo.com/companyimages/toysrus1.jpeg
Toys"R"Us
Incidents

No Incident

FAQ

Toys"R"Us company demonstrates a stronger AI Cybersecurity Score compared to American Eagle Outfitters Inc. company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Historically, Toys"R"Us company has disclosed a higher number of cyber incidents compared to American Eagle Outfitters Inc. company.

In the current year, Toys"R"Us company and American Eagle Outfitters Inc. company have not reported any cyber incidents.

Neither Toys"R"Us company nor American Eagle Outfitters Inc. company has reported experiencing a ransomware attack publicly.

Neither Toys"R"Us company nor American Eagle Outfitters Inc. company has reported experiencing a data breach publicly.

Neither Toys"R"Us company nor American Eagle Outfitters Inc. company has reported experiencing targeted cyberattacks publicly.

Neither American Eagle Outfitters Inc. company nor Toys"R"Us company has reported experiencing or disclosing vulnerabilities publicly.

Neither American Eagle Outfitters Inc. nor Toys"R"Us holds any compliance certifications.

Neither company holds any compliance certifications.

Neither American Eagle Outfitters Inc. company nor Toys"R"Us company has publicly disclosed detailed information about the number of their subsidiaries.

American Eagle Outfitters Inc. company employs more people globally than Toys"R"Us company, reflecting its scale as a Retail.

Neither American Eagle Outfitters Inc. nor Toys"R"Us holds SOC 2 Type 1 certification.

Neither American Eagle Outfitters Inc. nor Toys"R"Us holds SOC 2 Type 2 certification.

Neither American Eagle Outfitters Inc. nor Toys"R"Us holds ISO 27001 certification.

Neither American Eagle Outfitters Inc. nor Toys"R"Us holds PCI DSS certification.

Neither American Eagle Outfitters Inc. nor Toys"R"Us holds HIPAA certification.

Neither American Eagle Outfitters Inc. nor Toys"R"Us holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, including 9.3.0.x and 8.3.x display the full server stack trace when encountering an error within the GetCdfResource servlet.

Risk Information
cvss3
Base: 5.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Description

Pentaho Data Integration and Analytics Community Dashboard Editor plugin versions before 10.2.0.4, including 9.3.0.x and 8.3.x, deserialize untrusted JSON data without constraining the parser to approved classes and methods.

Risk Information
cvss3
Base: 8.8
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description

A security flaw has been discovered in CTCMS Content Management System up to 2.1.2. The impacted element is an unknown function in the library /ctcms/libs/Ct_Config.php of the component Backend System Configuration Module. The manipulation of the argument Cj_Add/Cj_Edit results in code injection. The attack can be executed remotely. The exploit has been released to the public and may be exploited.

Risk Information
cvss2
Base: 5.8
Severity: LOW
AV:N/AC:L/Au:M/C:P/I:P/A:P
cvss3
Base: 4.7
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 5.1
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A vulnerability was identified in CTCMS Content Management System up to 2.1.2. The affected element is the function Save of the file /ctcms/libs/Ct_App.php of the component Backend App Configuration Module. The manipulation of the argument CT_App_Paytype leads to code injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

Risk Information
cvss2
Base: 5.8
Severity: LOW
AV:N/AC:L/Au:M/C:P/I:P/A:P
cvss3
Base: 4.7
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 5.1
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Weblate is a web based localization tool. In versions prior to 5.15, it was possible to accept an invitation opened by a different user. Version 5.15. contains a patch. As a workaround, avoid leaving one's Weblate sessions with an invitation opened unattended.

Risk Information
cvss4
Base: 1.0
Severity: HIGH
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X