Data Breaches

VF Corp Says Data Breach Resulting From Ransomware Attack Impacts 35 Million

Apparel and footwear brands owner VF Corp shares more details on the impact of a December 2023 ransomware attack.

VF Corp hit by ransomware

The personal information of 35.5 million customers was stolen in a ransomware attack in December 2023, apparel and footwear brands owner and operator VF Corporation revealed on Thursday.

In mid-December, the Denver, Colorado-based company, which owns brands such as Dickies, The North Face, Smartwool, Timberland, and Vans, announced that it took certain systems offline in response to a ransomware attack that impacted its operations.

Right from the start, VF Corp said that the attackers were able to access certain corporate and personal information, and that a material impact from the incident was expected.

In a January 18 Form 8-K filing with the Securities and Exchange Commission (SEC), the company revealed that the hackers stole the personal information of approximately 35.5 million individual consumers.

While it did not specify what type of information was compromised in the data breach, VF Corp pointed out that it does not store Social Security numbers, bank account information, and payment card details, and that it has found no evidence that customer passwords were stolen.

The company also said that “the threat actor was ejected from VF’s IT systems on December 15, 2023,” and that it has since restored all impacted systems, albeit it continues to experience some minor operational impact.

Advertisement. Scroll to continue reading.

Following the shut down of systems to contain the attack, the company was unable to replenish retail store inventory and order fulfillment was delayed, which resulted in order cancellations, reduced demand on certain web stores, and the delay of some wholesale shipments.

VF Corp retail stores, brand e-commerce websites, and distribution centers are currently operating with minimal issues, the company said.

“While VF is still experiencing minor residual impacts from the cyber incident, VF has resumed retail store inventory replenishment and product order fulfillment, and is caught up on fulfilling orders that were delayed as a result of the cyber incident,” the company also noted.

VF also said that it expects the attack to have no other material impact than “the material impacts on VF’s business operations” disclosed in December and the incident might not influence its financial condition and results of operations.

Related: HMG Healthcare Says Data Breach Impacts 40 Facilities

Related: Law Firm Orrick Reveals Extensive Data Breach, Over Half a Million Affected

Related: 4.5 Million Individuals Affected by Data Breach at HealthEC

Related Content

Data Breaches

The hackers published the allegedly stolen information, including names, addresses, email addresses, and phone numbers.

Data Breaches

The root cause of the incident is believed to be a compromised AWS access key that was exposed in publicly available JavaScript build artifacts.

Data Breaches

Hackers stole the customers’ shipping information, including names, addresses, email addresses, and phone numbers.

Cybercrime

Affecting European contract logistics operations at eight Ceva warehouses, the incident caused shipment delays for multiple customers.

Data Breaches

Using social engineering, a threat actor accessed the computers of three employees and exfiltrated data from them.

Data Breaches

Hackers stole personal, medical, and health insurance information from a company’s data center.

Cybercrime

Maksim Silnikau was the creator and administrator of the ransomware group and involved in Angler EK’s distribution.

Data Breaches

Hackers stole personal information, medical records, and financial information from the organization’s server.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version