CSIDB logo
Incident

VF Corporation

Incident posture

Attack window
Oct 2020
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-12-25 00:00

Linked entities

Victim
VF Corporation
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The North Face experienced a credential-stuffing attack where attackers used credentials compromised from external sources to gain unauthorized access to customer accounts. The breach potentially exposed personal information such as purchase histories, saved product preferences, names, contact details, birthdays, and loyalty point balances, though payment card data remained unaffected as it was not stored. Unauthorized purchases may have occurred, leading the company to issue refunds, reset affected account passwords, and implement additional monitoring for suspicious login activity. Customers were cautioned against password reuse and phishing attempts following the incident.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On October 9, 2020, The North Face detected unauthorized access to customer accounts resulting from a credential-stuffing attack. Attackers leveraged usernames and passwords previously stolen from an unspecified third-party website to compromise accounts on the company’s e-commerce platform. The breach exposed customer-specific data, including purchase histories, items saved to favorites, billing and shipping addresses, full names, dates of birth, telephone numbers, email communication preferences, and loyalty program point balances. The company confirmed payment card details remained unaffected, as it does not store such information. While The North Face asserted the incident did not legally mandate breach notifications under applicable regulations, it proactively informed impacted customers out of caution. Evidence suggested attackers potentially executed unauthorized purchases using compromised accounts, though the scale of fraudulent transactions was not disclosed.

In response, The North Face initiated password resets for affected accounts to terminate unauthorized access. The company committed to refunding all fraudulent purchases attributed to the attack. It advised customers against password reuse across multiple websites, emphasizing that credentials exposed in unrelated breaches could facilitate future account takeovers. Additionally, The North Face implemented enhanced monitoring to identify patterns indicative of credential-stuffing activity, aiming to block similar attacks proactively. Customers were cautioned to scrutinize communications purporting to originate from the brand, as attackers might leverage stolen data for phishing campaigns. No forensic findings regarding attacker identity, infrastructure, or specific third-party sources of compromised credentials were disclosed publicly.

Sources

Sources available to members: 1 source.

CSIDB