FEDERALItem 1.05 · mandatoryHackingRetail & ConsumerRetailApparelData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICCriticalContained
VF Corporation
bd_0faf1d6a18a23d60 · schema v1 · pii pii-v1
Full breach record for VF Corporation →VF Corporation filed an 8-K/A amending its December 18, 2023 disclosure of a cybersecurity incident detected December 13, 2023. The threat actor was ejected December 15, 2023. Preliminary investigation estimates personal data of approximately 35.5 million individual consumers was stolen. VF does not retain SSNs, bank account, or payment card data; no evidence consumer passwords were acquired. Operations have substantially recovered.
SEC clockMateriality determined Dec 18, 2023 → Filed Jan 18, 202431d ✗ SEC 4-day late5 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_60c72c0902ed8ec8Leak Sitealphvfiled 2023-12-22(27d gap)Verified
Regulatory filings (1) · sorted by filing gap
- bd_b9037e596ac83596SEC 8-Kfiled 2023-12-18(31d gap)Candidate
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/103379/000119312524010243/d641969d8ka.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jan 18, 2024
- Raw hash
- 046f3cc66e2f3320a4c23ae1bf75e30c87ce35ef4c9ceaad614c695841a28558
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- VF Corporationnorm: vf
- SEC CIK
- 0000103379
- Domain
- vfc.com
Victim entity
- Name
- VF Corporationnorm: vf
- SEC CIK
- 0000103379
- Domain
- vfc.com
- Industry
- Retail & ConsumerllmNAICS 315250 · Cut and Sew Apparel Manufacturing (except Contractors)
Incident
- Discovered
- Dec 13, 2023
- Materiality determined
- Dec 18, 2023
- Notification sent
- —
- Affected individuals
- 35,500,000
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified federal law enforcementNotified relevant regulatory authorities as required under applicable law
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- SEC 4-day late · 31d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Dec 18, 2023→ Filed: Jan 18, 202431d cal. 4 business days SEC 4-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.