Data Breaches

VF Corp Disrupted by Cyberattack, Online Operations Impacted

VF Corporation (NYSE: VFC), which owns and operates some of the biggest apparel and footwear brands, has been hit by a ransomware attack that included the theft of sensitive corporate and personal data.

VF Corp hit by ransomware

VF Corporation (NYSE: VFC), a company that owns and operates some of the biggest apparel and footwear brands, has been hit by a ransomware attack that included the theft of sensitive corporate and personal data.

In a filing with the SEC, VF Corp said the hackers disrupted business operations — including its ability to fulfill ecommerce orders — and hijacked data from the company, including personal data. 

The company did not provide additional details on the stolen data, or whether third-party customer data was exposed.

“[We are] working to bring the impacted portions of its IT systems back online and implement workarounds for certain offline operations with the aim of reducing disruption to its ability to serve its retail and brand e-commerce consumers and wholesale customers,” VF Corp said.

The mega-corporation, which owns brands that include The North Face, Vans, Timberland, Smartwool and Dickies, said its retail stores around the world remain open but warned that it is experiencing “certain operational disruptions.” 

VF Corporation is one of the world’s largest apparel, footwear and accessories companies, owning a portfolio of well-known global brands

VF Corp said consumers are still able to place orders on most of the brand e-commerce sites globally but the company’s ability to fulfill orders is currently impacted. 

The Denver, Colorado-based company noted that the full scope, nature and impact of the incident are not yet known and cautioned that it is “reasonably likely to continue to have a material impact on business operations until recovery efforts are completed.” 

Advertisement. Scroll to continue reading.

VF Corporation is one of the world’s largest apparel, footwear and accessories companies and sells products in more than 100 countries. The company has revenue of more than $11.6 billion, with roughly 35,000 employees around the world and 1,265 owned retail stores.

Shares of the company are trading down nearly 9% at the time of publishing.

News of the incident comes on the same day that the SEC’s new cyber incident disclosure requirements come into effect, requiring companies to disclose any “material breach” within four business days of discovering that the incident has material impact.

Related: MongoDB Confirms Hack, Says Customer Data Stolen

Related: Food Giant Kraft Heinz Targeted by Ransomware Group

Related: Delta Dental Says Breach Exposed 7 Million Customers

Related: Toyota Germany Customer Data Stolen in Ransomware Attack

Related Content

Data Breaches

The PEAR ransomware group claimed to have stolen 3 TB of information from the medical business management company.

Data Breaches

A hacker claims to have stolen the information of 2 million Origin Energy customers and is threatening to leak it. 

Data Breaches

The Anubis ransomware group claims to have stolen 1 TB of confidential data from the Coca-Cola subsidiary.

Data Breaches

Hackers exfiltrated personal, financial, and health information from the company’s Oracle EBS instance in August 2025.

Cybercrime

The company disconnected its systems on July 13 and is starting to gradually restore operations.

Ransomware

The company has yet to determine the full scope, nature, and impact of the incident.

Cybercrime

The D1R cybercrime group claimed to have stolen valuable data from Synopsys and Bosch, threatening to leak it unless a ransom is paid. 

Cybercrime

Angelo Martino, a former ransomware negotiator, was sentenced to 70 months for helping the BlackCat/Alphv group.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version