Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Thousands Hit by The North Face Credential Stuffing Attack

Posted on June 4, 2025June 4, 2025 By CWS

Sports activities attire and footwear large VF Company is notifying over 2,800 people that their private data was compromised in a current credential stuffing assault geared toward The North Face web site.

Credential stuffing happens when menace actors leverage electronic mail addresses, usernames, and passwords compromised in a earlier information breach to entry accounts on a distinct on-line service the place the identical credentials have been used.

In accordance with notification letters VF Company despatched this week to the impacted people, copies of which had been submitted to a number of regulators, a menace actor employed this system on April 23 towards a small set of person accounts on thenorthface.com web site.

“Primarily based on our investigation, we imagine that the attacker beforehand gained entry to your electronic mail tackle and password from one other supply (not from us) after which used those self same credentials to entry your account on our web site,” the corporate’s notification letter reads.

VF Company says it found the suspicious exercise on the identical day, and knowledgeable the Maine Legal professional Normal’s Workplace {that a} whole of two,861 person accounts had been compromised.

The marketing campaign resulted within the attackers having access to the knowledge saved within the compromised accounts, corresponding to names, addresses, electronic mail addresses, dates of beginning, telephone numbers, person preferences, and particulars on the objects bought on the web site.

The corporate underlines that cost card data was not compromised as a result of it doesn’t retailer such information on its web site.

“We solely retain a ‘token’ linked to your cost card, and solely our third-party cost card processor retains cost card particulars. The token can’t be used to provoke a purchase order wherever apart from on our web site. Accordingly, your bank card data isn’t in danger because of this incident,” it says.Commercial. Scroll to proceed studying.

VF Company says it disabled the passwords for the impacted accounts instantly after discovering the assaults, and is urging customers to create robust, distinctive passwords to keep away from related incidents.

“We strongly encourage you to not use the identical password on your account at our web site that you just use on different web sites. If a breach happens on a kind of different web sites, an attacker might use your electronic mail tackle and password to entry your account at our web site,” the corporate explains.

Impacted customers are suggested to be cautious of phishing assaults as menace actors might use the compromised data to impersonate the group.

Headquartered in Denver, Colorado, VF Company owns 11 manufacturers, together with Eastpak, JanSport, The North Face, and Timberland.

Associated: A Information to Safety Investments: The Anatomy of a Cyberattack

Associated: MainStreet Financial institution Knowledge Breach Impacts Buyer Cost Playing cards

Associated: Amtrak Says Visitor Rewards Accounts Hacked in Credential Stuffing Assaults

Associated: Staffing Agency Robert Half Says Hackers Focused Over 1,000 Buyer Accounts

Security Week News Tags:Attack, Credential, Face, Hit, North, Stuffing, Thousands

Post navigation

Previous Post: 35,000 Solar Power Systems Exposed to Internet
Next Post: Malicious PyPI, npm, and Ruby Packages Exposed in Ongoing Open-Source Supply Chain Attacks

Related Posts

Google Finds Data Theft Malware Used by Russian APT in Select Cases Security Week News
480,000 Catholic Health Patients Impacted by Serviceaide Data Leak Security Week News
Security Firm Andy Frain Says 100,000 People Impacted by Ransomware Attack Security Week News
Google Warns of Vishing, Extortion Campaign Targeting Salesforce Customers Security Week News
Dutch Intelligence Agencies Say Russian Hackers Stole Police Data in Cyberattack Security Week News
Rising Tides: Kelley Misata on Bringing Cybersecurity to Nonprofits Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Empower Users and Protect Against GenAI Data Loss
  • Cybersecurity M&A Roundup: 42 Deals Announced in May 2025
  • US to Offer $10 Million Reward for Details About RedLine Malware Developer
  • MIND Raises $30 Million for Data Loss Prevention
  • Why More Security Leaders Are Selecting AEV

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2025
  • May 2025

Recent Posts

  • Empower Users and Protect Against GenAI Data Loss
  • Cybersecurity M&A Roundup: 42 Deals Announced in May 2025
  • US to Offer $10 Million Reward for Details About RedLine Malware Developer
  • MIND Raises $30 Million for Data Loss Prevention
  • Why More Security Leaders Are Selecting AEV

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News