HackingStolen CredentialsTargetedIDENTITY_BASICCREDENTIALSLowContained
VF Corporation
bd_e7d494563a900fab · schema v1 · pii pii-v1
Full breach record for VF Corporation →VF Outdoor, LLC (The North Face, Timberland) notified consumers of a credential stuffing attack on March 13, 2025. Attackers used stolen credentials to access accounts. Compromised data included names, emails, passwords, addresses, and DOBs. No payment card data was compromised. VF disabled passwords and advised users to reset them.
Leak gap clock✗ Leak >180d26 days discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 2 about the same incident.View merged incident
A leak claim by alphv about this victim predates this filing by 473 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_4ef3ab7396e1387cVermont State AGfiled 2025-05-29(51d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2025-04-08-vf-outdoor-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 8, 2025
- Raw hash
- 3726350ff777f185c3042e6a92e14146b2c9383ef5276e052f8e909af32dba0a
Reporting entity
- Name
- VF Corporationnorm: vf
- Domain
- vfc.com
Victim entity
- Name
- VF Corporationnorm: vf
- Domain
- vfc.com
Incident
- Discovered
- Mar 13, 2025
- Materiality determined
- —
- Notification sent
- Apr 8, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1110 Brute ForceT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 26 days(26 days from discovery to filing)
- Compliance flags
- Leak >180dVT AG >14 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.