DisclosureLens
HackingRetail & ConsumerRetailStolen CredentialsCustomer Data InvolvedPIIIdentity (basic)CredentialsFinancial accountMediumContained

VF Outlet

bd_8080a1d4eadad826 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Sep 28, 2016

To disclose

Affected · nationwide

7,28412 in this filing

Confidence

66%
Full breach record for VF Outlet

VF Outlet, Inc. notified Montana and other state AGs of a data breach where an unauthorized individual accessed a third-party server hosting vfoutlet.com between April 17 and August 26, 2016. The incident exposed personal information, including names, addresses, emails, passwords, and payment card data, for 7,284 individuals. VF Outlet resolved the vulnerability and offered one year of credit monitoring.

Incident timeline

Apr 17, 2016

Begins

Sep 28, 2016

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed7,284 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.