CSIDB logo
Incident

TOMS Shoes

Incident posture

Attack window
Oct 2019
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-02 00:00

Linked entities

Victim
TOMS Shoes
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Oct 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A hacker compromised TOMS Shoes' mailing list to send subscribers a message encouraging them to disconnect from digital screens and engage with the physical world. The perpetrator, identifying as Nathan, criticized malicious hackers for exploiting personal data and urged ethical behavior, while apologizing to the company for the intrusion. The retailer acknowledged unauthorized access affecting its email and social media platforms, advising customers to avoid interacting with suspicious communications.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On or around October 6, 2019, an unauthorized individual using the alias "Nathan" compromised the mailing list systems of footwear retailer TOMS Shoes. The attacker gained access to the company's email distribution channels and sent a message to subscribers with the subject line "hey you, don’t look at a digital screen all day, theres a world out there that you’re missing out on." The content advocated for reduced screen time and engagement with the physical world, stating "just felt some people need that." Nathan claimed the intrusion method was simple but did not disclose technical specifics. The message also contained ethical appeals to other hackers, condemning malicious activities like selling private information and cyberbullying while urging positive behavior toward others. There was no indication in the communication that customer data was exfiltrated or monetized.

TOMS Shoes confirmed the security incident through an official statement, acknowledging unauthorized activity affecting both email and social media communications platforms. The company advised customers not to interact with suspicious messages while initiating an internal investigation. Nathan concluded their message with an apology to TOMS, writing "Dear TOMS, sorry for hacking you guys. No hard feelings pls?" The breach's primary operational impact was the unauthorized use of communication channels to distribute non-malicious content, requiring TOMS to temporarily suspend normal mailing list operations during their response. No financial motives, data theft claims, or system destruction evidence appeared in the attacker's communications or company disclosures.

Sources

Sources available to members: 1 source.

CSIDB