Clustered 3 filings across 3 jurisdictions · filed Nov 5, 2020. View entity profile → Other incidents for this victim →
incident inc_1ba1c053a09f4574 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
CA DE OR
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
all State AG
Earliest sighting first · deep chronology in Litigation Timeline
Oct 8, 2020 → Oct 9, 2020
When the intrusion reportedly occurred, per the linked filings
Oct 9, 2020
Reported by CALIFORNIA AG, OREGON AG, DELAWARE AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
VF Outdoor (The North Face) disclosed a credential stuffing attack on October 8-9, 2020. Attackers used stolen credentials from external sources to access user accounts. Compromised data included names, email addresses, passwords, addresses, phone numbers, and VIPeak loyalty points. Payment card numbers were not stored on-site and were not compromised. The company disabled passwords for affected accounts and implemented suspicious login monitoring.
VF Outdoor, LLC doing business as The North Face® reported a data breach to the Oregon Attorney General. The breach was reported on 2020-11-05. The breach occurred during 10/8/2020 - 10/9/2020. The breach was discovered on 10/9/2020. 34,582 individuals were affected. Notice was sent on 11/5/2020.
Affected (this filing): 34,582
VF Outdoor (The North Face) reported a credential stuffing attack on thenorthface.com occurring October 8-9, 2020. The attacker accessed user accounts using stolen credentials, viewing names, addresses, VIPeak points, and purchase history. Payment card data was tokenized and not accessed. 34,582 individuals were affected (59 in Delaware). Notices were sent November 5, 2020.
Affected (this filing): 34,582