HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
VF Outdoor, LLC
bd_a095d154f34a4bcb · schema v1 · pii pii-v1
Full breach record for VF Outdoor, LLC →VF Outdoor (The North Face) reported a credential stuffing attack on thenorthface.com occurring October 8-9, 2020. The attacker accessed user accounts using stolen credentials, viewing names, addresses, VIPeak points, and purchase history. Payment card data was tokenized and not accessed. 34,582 individuals were affected (59 in Delaware). Notices were sent November 5, 2020.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_0209420b689cb2a2California State AGfiled 2020-11-05Verified
- bd_4b3f3642dc27ab49Oregon State AGfiled 2020-11-05Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2020/11/VF-Outdoor-Notice-of-Breach-to-AG.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 5, 2020
- Raw hash
- cccdba67bfc9d30ee7acd999fdb3c3c48e7887dad2707054086d57d38dfb6fb9
Reporting entity
- Name
- DLA PIPER LLP (US)norm: dla piper llp us
Victim entity
- Name
- VF Outdoor, LLCnorm: vf outdoor
Incident
- Discovered
- Oct 9, 2020
- Materiality determined
- —
- Notification sent
- Nov 5, 2020
- Affected individuals
- 34,582
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 27 days(27 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.