The clothing company "The North Face" fell victim to a credential stuffing attack that resulted in the breach of 194,905 accounts on the website thenorthface.com.
See also: FBI: Home proxies exploited in credential stuffing attacks

In a credential stuffing attack, malicious actors use email address/username and password combinations taken from previous data breachesto attempt to compromise user accounts on other websites.
The success of these attacks relies on the practice of password recycling, where an individual uses the same credentials across multiple online platforms.
The credential stuffing attack on The North Face website began on July 26, 2022, but the website administrators detected the unusual activity on August 11, 2022, and were able to stop it on August 19, 2022.
After investigating the attack, The North Face found that the attackers were able to compromise nearly 200,000 accounts using valid credentials, potentially gaining access to the following customer information:
Full name
Purchase history
Billing address
Shipping address
Phone number
Account creation date
Genus
XPLR Pass Rewards Entries
See also: General Motors (GM): Credential stuffing attack exposed customer data

Payment details, such as credit card data, are not stored on the website, so attackers could not access sensitive financial information.
In response to the incident, The North Face's parent company, VF Corporation (formerly Vanity Fair Mills), is sending data breach notifications to affected customers. In addition, all user passwords have been reset and all payment card tokens on accounts accessed by unauthorized attackers have been deleted.
As a result, affected customers with an account on the site will need to enter a new password and re-enter their payment card details to make a purchase.
See also: InterContinental Hotels Group victim of cyberattack
Of course, affected users should choose a unique, strong (long) password and avoid the convenience of recycling credentials. Also, if customers use the same passwords on other online platforms, they should change them immediately to avoid additional breaches.
