VF Corporation
ent_204a92d728131e0d2f2023bf
Disclosures
11
State AG · SEC 10-K Item 1C · SEC 8-K · Leak Site · 6 jurisdictions
Incidents
4
filings grouped by incident
Max affected reported
35,500,000
nationwide · SEC 8-K FEDERAL
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- VF Corporation
- Normalized
- vf— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- vfc.com
Disclosure history (11)newest first
- 🍁Vermont State AGas victim2025-05-29
VF Outdoor, LLC (doing business as The North Face) disclosed a credential stuffing attack on thenorthface.com discovered on April 23, 2025. Attackers used credentials stolen from other sources to access user accounts. Compromised data may include names, email addresses, passwords, shipping addresses, and payment preferences. No payment card numbers were stored or compromised. VF Outdoor disabled passwords and notified affected consumers.
- 🍁Vermont State AGas victim2025-04-08
VF Outdoor, LLC (The North Face, Timberland) notified consumers of a credential stuffing attack on March 13, 2025. Attackers used stolen credentials to access accounts. Compromised data included names, emails, passwords, addresses, and DOBs. No payment card data was compromised. VF disabled passwords and advised users to reset them.
- 🐻California State AGas victim2025-04-04
VF Outdoor, LLC (dba The North Face/Timberland) disclosed a credential stuffing attack on March 13, 2025. Attackers used stolen credentials from other breaches to access user accounts. Affected data included names, emails, shipping addresses, and purchase history. Payment card details were not compromised. The company disabled passwords and urged users to reset them.
- 🦞Maine State AGas victim2025-04-04
VF Outdoor, LLC (a VF Corporation outdoor brands subsidiary) reported a data breach to the Maine Attorney General. The breach occurred and was discovered on 2025-03-13, affecting 15,713 individuals total, including 27 Maine residents. The cause was reported only as 'Other' with no specific information categories enumerated on the form. Electronic consumer notifications were sent on 2025-04-04. Identity theft protection services were not offered. Outside counsel: Andrew Serwin, DLA Piper LLP (US).
- FEDERALSEC 10-K Item 1Cas victim2024-05-23
VF Corporation's Fiscal 2024 Form 10-K Item 1C references a previously disclosed December 2023 cybersecurity incident affecting its IT systems. The company states impacts were not material to financial condition or results of operations. VF is seeking reimbursement from cybersecurity insurers. No specifics on attack vector, affected individuals, or data types are provided in this Item 1C narrative.
- FEDERALSEC 8-Kas victim2024-01-18
VF Corporation filed an 8-K/A amending its December 18, 2023 disclosure of a cybersecurity incident detected December 13, 2023. The threat actor was ejected December 15, 2023. Preliminary investigation estimates personal data of approximately 35.5 million individual consumers was stolen. VF does not retain SSNs, bank account, or payment card data; no evidence consumer passwords were acquired. Operations have substantially recovered.
- GLOBALLeak Siteas victim2023-12-22
VF Corporation is an American global apparel and footwear company founded in 1899 by John Barbey and headquartered in Denver, Colorado. The company's 13 brands are organized into three categories: Outdoor, Active and Work. In 2015, the company controlled 55% of the U.S. backpack market with the JanSport, Eastpak, Timberland, and The North Face brands.
- FEDERALSEC 8-Kas victim2023-12-18
On December 13, 2023, V.F. Corporation detected unauthorized activity on a portion of its IT systems. A threat actor encrypted some IT systems and stole data, including personal data. The Company activated its incident response plan, engaged external cybersecurity experts, shut down some systems, and notified federal law enforcement. The incident has had and is reasonably likely to continue to have a material impact on business operations. Disclosed via Item 1.05 8-K filed December 18, 2023.
- 🦫Oregon State AGas victim2022-09-06
VF Outdoor, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2022-09-06. The breach occurred during 7/26/2022 - 8/20/2022. The breach was discovered on 8/11/2022. 194,905 individuals were affected. Notice was sent on 9/5/2022.
- 🦞Maine State AGas victim2022-09-06
VF Outdoor, LLC, the parent company of brands like Vans and The North Face, experienced a credential stuffing attack. Attackers used stolen usernames and passwords from other breaches to gain unauthorized access to customer accounts.
- 🐻California State AGas victim2022-09-05
VF Outdoor, LLC (doing business as The North Face and Vans) disclosed a credential stuffing attack targeting thenorthface.com and vans.com. The incident occurred between July 26 and August 20, 2022, with unauthorized access detected on August 11, 2022. Attackers obtained email addresses and passwords, potentially accessing account details including names, addresses, dates of birth, and phone numbers. Payment card data was not compromised. The incident affected approximately 194,905 individuals in the United States (162,823 North Face + 32,082 Vans). Response actions included disabling passwords and erasing payment card tokens.