HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICCREDENTIALSLowContained
VF Outdoor, LLC
bd_0209420b689cb2a2 · schema v1 · pii pii-v1
Full breach record for VF Outdoor, LLC →VF Outdoor (The North Face) disclosed a credential stuffing attack on October 8-9, 2020. Attackers used stolen credentials from external sources to access user accounts. Compromised data included names, email addresses, passwords, addresses, phone numbers, and VIPeak loyalty points. Payment card numbers were not stored on-site and were not compromised. The company disabled passwords for affected accounts and implemented suspicious login monitoring.
California clockDiscovered Oct 9, 2020 → Notified Nov 5, 202027d ✓ CA 60-day OK27 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_4b3f3642dc27ab49Oregon State AGfiled 2020-11-05Candidate
- bd_a095d154f34a4bcbDelaware State AGfiled 2020-11-05Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-195859
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 5, 2020
- Raw hash
- 055c7f47b59e27fe8ba578e63a7a32c29cd669ff9c141eb39e03f4710bffea3f
Reporting entity
- Name
- VF Outdoor, LLCnorm: vf outdoor
Victim entity
- Name
- VF Outdoor, LLCnorm: vf outdoor
Incident
- Discovered
- Oct 9, 2020
- Materiality determined
- Nov 5, 2020
- Notification sent
- Nov 5, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1110.003 Credential StuffingT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed breach notification with California Office of the Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 27 days(27 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 27d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 9, 2020→ Notified: Nov 5, 202027d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.