The North Face discloses April credential stuffing attack on customer accounts

Organization
The North Face (VF Outdoor)
Exploit
Credential Compromise
Industry
Retail

VF Outdoor, the parent of outdoor apparel brand The North Face, told customers that an attacker had used stolen login credentials to break into accounts on thenorthface.com. The company said it detected unusual activity on 23 April 2025 and described the incident as a small-scale credential stuffing attack, in which usernames and passwords taken from unrelated breaches are replayed against a target's login page.

In a filing with the Maine attorney general reported by The Record, VF put the number of affected accounts at 2,861. A parallel notification was filed in Vermont. Information visible in a compromised account could include the customer's name, email address, shipping address, purchase history and saved preferences, and in some cases date of birth and telephone number. The company said payment card details were not exposed because those are held by a third-party processor rather than on its own site.

The North Face disabled passwords on the site and required customers to set new ones, and it urged them not to reuse passwords across websites. It did not offer identity protection services, and said it was notifying customers voluntarily because it did not believe the incident met the threshold for a required breach notice.

Coverage noted this was not the brand's first such incident. VF reported a credential stuffing attack affecting close to 200,000 customers in 2022, and disclosed a ransomware attack in December 2023 that disrupted order fulfillment.

Sources