The North Face discloses April credential stuffing attack on customer accounts
- Organization
- The North Face (VF Outdoor)
- Exploit
- Credential Compromise
- Industry
- Retail
VF Outdoor, the parent of outdoor apparel brand The North Face, told customers that an attacker had used stolen login credentials to break into accounts on thenorthface.com. The company said it detected unusual activity on 23 April 2025 and described the incident as a small-scale credential stuffing attack, in which usernames and passwords taken from unrelated breaches are replayed against a target's login page.
In a filing with the Maine attorney general reported by The Record, VF put the number of affected accounts at 2,861. A parallel notification was filed in Vermont. Information visible in a compromised account could include the customer's name, email address, shipping address, purchase history and saved preferences, and in some cases date of birth and telephone number. The company said payment card details were not exposed because those are held by a third-party processor rather than on its own site.
The North Face disabled passwords on the site and required customers to set new ones, and it urged them not to reuse passwords across websites. It did not offer identity protection services, and said it was notifying customers voluntarily because it did not believe the incident met the threshold for a required breach notice.
Coverage noted this was not the brand's first such incident. VF reported a credential stuffing attack affecting close to 200,000 customers in 2022, and disclosed a ransomware attack in December 2023 that disrupted order fulfillment.
Sources
- The Record, Nearly 3,000 North Face website customer accounts breached as retail incidents continue
- The Register, Crooks fleece The North Face accounts with recycled logins
- Forbes, Password Attack: The North Face Confirms Data Breach
- Malwarebytes Labs, The North Face warns customers about potentially stolen data