VF Corporation
bd_5b713f4a386a366d · schema v1 · pii pii-v1
Full breach record for VF Corporation →VF Outdoor, LLC (doing business as The North Face and Vans) disclosed a credential stuffing attack targeting thenorthface.com and vans.com. The incident occurred between July 26 and August 20, 2022, with unauthorized access detected on August 11, 2022. Attackers obtained email addresses and passwords, potentially accessing account details including names, addresses, dates of birth, and phone numbers. Payment card data was not compromised. The incident affected approximately 194,905 individuals in the United States (162,823 North Face + 32,082 Vans). Response actions included disabling passwords and erasing payment card tokens.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_3de93dca39660db2Oregon State AGfiled 2022-09-06(1d gap)Verified
- bd_7d4bed9d72ecad10Maine State AGfiled 2022-09-06(1d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-556917
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 5, 2022
- Raw hash
- 13055d008ce6220d3f9f73fa7c4e171baf6203db2b41f25ffe6971fd1402771f
Reporting entity
- Name
- VF Corporationnorm: vf
- Domain
- vfc.com
Victim entity
- Name
- VF Corporationnorm: vf
- Domain
- vfc.com
Incident
- Discovered
- Aug 11, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 194,905
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1110 Brute Force
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 25 days(25 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.