FEDERALItem 1.05 · mandatoryMalwareRetail & ConsumerRetailApparelRansomwareCapture Stored DataData EncryptedData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowActive
VF Corporation
bd_b9037e596ac83596 · schema v1 · pii pii-v1
Full breach record for VF Corporation →On December 13, 2023, V.F. Corporation detected unauthorized activity on a portion of its IT systems. A threat actor encrypted some IT systems and stole data, including personal data. The Company activated its incident response plan, engaged external cybersecurity experts, shut down some systems, and notified federal law enforcement. The incident has had and is reasonably likely to continue to have a material impact on business operations. Disclosed via Item 1.05 8-K filed December 18, 2023.
SEC clockMateriality determined Dec 15, 2023 → Filed Dec 18, 20233d ✓ SEC 4-day OK5 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_60c72c0902ed8ec8Leak Sitealphvfiled 2023-12-22(4d gap)Verified
Regulatory filings (1) · sorted by filing gap
- bd_0faf1d6a18a23d60SEC 8-Kfiled 2024-01-18(31d gap)Verified
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/103379/000095012323011228/d659095d8k.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Dec 18, 2023
- Raw hash
- b1d4ce41581cb2d6a963b3bbe470c0d5e91e76b99841af9af202d481566efbe9
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- VF Corporationnorm: vf
- SEC CIK
- 0000103379
- Domain
- vfc.com
Victim entity
- Name
- VF Corporationnorm: vf
- SEC CIK
- 0000103379
- Domain
- vfc.com
- Industry
- Apparel and Footwear
- Industry
- Retail & ConsumerllmNAICS 315250 · Cut and Sew Apparel Manufacturing (except Contractors)
Incident
- Discovered
- Dec 13, 2023
- Materiality determined
- Dec 15, 2023
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified and is cooperating with federal law enforcementFiled Item 1.05 disclosure with the SEC
Compliance
- Time to disclose
- 5 days(5 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 3d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Dec 15, 2023→ Filed: Dec 18, 20233d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.