HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICCREDENTIALSBEHAVIORLowContained
VF Corporation
bd_7a61bbf9690c8142 · schema v1 · pii pii-v1
Full breach record for VF Corporation →VF Outdoor, LLC (dba The North Face/Timberland) disclosed a credential stuffing attack on March 13, 2025. Attackers used stolen credentials from other breaches to access user accounts. Affected data included names, emails, shipping addresses, and purchase history. Payment card details were not compromised. The company disabled passwords and urged users to reset them.
Leak gap clock✗ Leak >180d22 days discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_f648e3c5ed46091fMaine State AGfiled 2025-04-04Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-600989
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 4, 2025
- Raw hash
- cb4ab1a572046f363c2bfd9761cd17db4410c7e78159b2000e38cd1bcbd19924
Reporting entity
- Name
- VF Corporationnorm: vf
- Domain
- vfc.com
Victim entity
- Name
- VF Corporationnorm: vf
- Domain
- vfc.com
Incident
- Discovered
- Mar 13, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALSBEHAVIOR
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 22 days(22 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.