HomeSecurityThe North Face: Credential stuffing attacks allowed data breach

The North Face: Credential stuffing attacks allowed data breach

The North Face, a leading outdoor clothing and equipment company, is warning its customers of a data breach, following attacks credential stuffing that targeted its website in April 2025.

The North Face Credential stuffing data breach

The company, which is part of VF Corporation along with Vans, Timberland and Dickies, said the attacks involved attempts to gain unauthorized access to user accounts through automated methods. The cybercriminals used combinations of usernames and passwords that had been leaked from previous breaches of other services — a tactic that relies on user credential recycling (users using the same credentials across different accounts).

The North Face detected “unusual activity” on its website, thenorthface.com, on April 23, 2025, and immediately launched an internal investigation. The company has already sent data breach notifications to affected customers

See also: Cartier reveals customer data breach

It is worth noting that such attacks can be prevented or completely thwarted when accounts are protected by multi-factor authentication (MFA) mechanisms. However, many users continue to use common or repeated credentials across different platforms, making systems more vulnerable.

Based on the available evidence, the attackers gained access to information such as name, purchase history, shipping address, email, date of birth and phone number. The company clarifies that no payment data was affected, as transactions are managed through an external provider, and it only retains the necessary token to complete purchases.

The North Face: Repeated violations and absence of MFA

This new data breach once again highlights weaknesses in The North Face's cybersecurity policy. Despite the volume of personal data it manages, the company has not enforced mandatory multi-factor authentication (MFA) for all users. As a result, breaches are common.

See also: Atlantis AIO: New platform enables automated credential stuffing attacks

The latest incident is the fourth credential stuffing attack since 2020. Just a few months ago, on March 13, 2025, parent company VF Outdoor announced that hackers had breached thenorthface.com and timberland.com, exposing 15,700 accounts. This was preceded by two other breaches, in 2020 and 2022, that affected a total of over 200,000 customers.

Additionally, in December 2023, a ransomware attack led to the leakage of personal data of 35 million The North Face customers.

See also: LexisNexis: Data broker announces data breach

The North Face: Credential stuffing attacks allowed data breach
The North Face: Credential stuffing attacks allowed data breach

Defense against credential stuffing

  • Use strong passwords ( which means they consist of letters, symbols, and numbers).
  • Use different passwords for different servicesso that all accounts cannot be accessed if one password is leaked.
  • Implement multi-factor authentication. This means that even if someone has your username and password, they'll need a second factor – usually a code sent to your phone – to gain access.
  • Reject requests outside of company sites, block IP addresses with bad reputation, monitor and respond to suspicious connections.
  • Regularly monitor accounts for any suspicious activity. If you notice anything unusual, change your password immediately and contact your service.

Source: www.bleepingcomputer.com

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS