Thousands of North Face customers accounts hacked, personal data stolen

The North Face jacket
(Image credit: Shutterstock.com / Kamil Zajaczkowski)

Outdoor clothing brand The North Face has been hit by a major cyberattack that has seen nearly 200,000 customer accounts hacked.

The company confirmed that its thenorthface.com website was impacted by a large-scale credential stuffing attack that has resulted in the hacking of 194,905 customer accounts.

The attackers were able to steal user email addresses and passwords, as well as personal information stored on user accounts - however it appears no payment or card data was affected.

North Face breach

The company is now contacting affected customers, informing them of the attack and instructing them to update their passwords immediately.

In a breach notification document, The North Face told customers that it had detected "unusual activity" on its website on August 11 2022. Following an investigation, it found had attackers had launched a credential stuffing attack against the website at some point between July 26 and August 19, 2022.

Credential stuffing attacks see criminals use login or authentication details such as email addresses and passwords taken from previous data breaches or leaks in an attempt to find other accounts to log in to.

In this case, The North Face confirmed the attackers would have been able to access details including full names, purchase history, billing and shipping addresses, telephone numbers and even gender.

Fortunately, no payment details were stored on the website, so all credit and debit card data remained safe.

"We do not keep a copy of payment card details on thenorthface.com. We only retain a "token" linked to your payment card, and only our third-party payment card processor keeps payment card details," the company noted.

"The token cannot be used to initiate a purchase anywhere other than on thenorthface.com."

Affected user accounts and passwords have been reset, with users instructed to pick strong and unique new passwords that are not used on any other websites or platforms.

Via BleepingComputer

Mike Moore
Deputy Editor, TechRadar Pro

Mike Moore is Deputy Editor at TechRadar Pro. He has worked as a B2B and B2C tech journalist for nearly a decade, including at one of the UK's leading national newspapers and fellow Future title ITProPortal, and when he's not keeping track of all the latest enterprise and workplace trends, can most likely be found watching, following or taking part in some kind of sport.

Read more
A hacker wearing a hoodie sitting at a computer, his face hidden.
North Pole Company data breach exposes details on half a million users
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
Representational image of data security
Travel data of almost 500,000 users exposed in Daytrip leak
How to prevent cyberattacks
NTT admits hackers accessed details of almost 18,000 corporate customers in cyberattack
Suitcase next to a bed in a hotel
Millions of hotel users see personal info checked out in huge data leak
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
Latest in Cyber Crime
A person scanning a QR code on a smartphone
Quishing is the new QR code scam you need to watch out for – here's how to stay safe
Ransomware on the rise: how small and medium-sized businesses can achieve cyber resilience during turbulent times
Ransomware on the rise: how small and medium-sized businesses can achieve cyber resilience during turbulent times
Text Phishing Scams
Do not fall for this dangerous Amazon shopping scam
Cyber-security
Safeguarding against next-gen cyber risks
The North Face jacket
Thousands of North Face customers accounts hacked, personal data stolen
Smartphone hacked with data flow in the background
9 signs your phone has been hacked
Latest in News
Apple iPhone 16 Pro Max REVIEW
The latest iPhone 17 Pro Max leak may have given us another look at its upcoming redesign
Half-Life running on a smartwatch
This Redditor installed a game engine on their smartwatch, and now it runs Doom, Quake, and Half-Life
Samsung Galaxy Z Fold 6
The Samsung Galaxy Z Fold 7 could be in line for a Galaxy S25 Ultra-level camera upgrade
Data leak
Hacked Tata Technologies data leaked by ransomware gang
Three iPhones on a green and blue background showing trails on Apple Maps
iOS 18.4 will give your iPhone a much-needed maps upgrade – but only if you're in the EU
A close up of Billy Bob Thornton's Tommy Norris in Paramount Plus' Landman TV series
The Taylor Sheridan supremacy lives on at Paramount+ as Landman gets renewed for season 2