8-K/A: VF Corporation Provides Update on Cyberattack, 35.5 Million Consumers Impacted
Cybersecurity Incident Update
VF Corporation reports that a cyberattack resulted in the theft of personal data of approximately 35.5 million consumers, but the company believes the material impact on its business operations is limited and no longer ongoing.
Summary
- VF Corporation experienced a cybersecurity incident on December 13, 2023, involving unauthorized access to its IT systems.
- The company took immediate steps to contain the incident, including shutting down some systems and engaging external cybersecurity experts.
- VF believes the threat actor was ejected from its systems by December 15, 2023.
- The cyberattack resulted in the theft of personal data of approximately 35.5 million consumers.
- VF does not collect or retain social security numbers, bank account information, or payment card details in its direct-to-consumer systems.
- There is no evidence to date that consumer passwords were acquired by the threat actor.
- The company experienced disruptions to operations, including retail store inventory replenishment and order fulfillment, but these issues have been largely resolved.
- VF has substantially restored its IT systems and data impacted by the incident.
- The company believes the material impact on its business operations is limited and no longer ongoing.
- VF also believes the impacts of the cyber incident are not material and are not reasonably likely to be material to its financial condition and results of operations.
- VF will seek reimbursement for costs and losses from its cybersecurity insurers, but the timing and amount of reimbursements are unknown.
Sentiment
Score: 6
Explanation: While the data breach is a significant negative, the company's quick response, containment of the incident, and limited impact on operations are positive. The lack of sensitive financial data being compromised is also a positive. The overall sentiment is neutral to slightly negative due to the large number of consumers affected.
Positives
- VF believes the threat actor was ejected from its systems within two days of detection.
- The company has substantially restored its IT systems and data.
- VF believes the material impact on its business operations is limited and no longer ongoing.
- VF does not collect or retain sensitive financial information like social security numbers, bank account details, or payment card information in its direct-to-consumer systems.
- There is no evidence to date that consumer passwords were acquired by the threat actor.
- VF is seeking reimbursement from its cybersecurity insurers for costs and losses.
Negatives
- The cyberattack resulted in the theft of personal data of approximately 35.5 million consumers.
- VF experienced disruptions to operations, including retail store inventory replenishment and order fulfillment.
- The company experienced impacts such as the cancellation by customers and consumers of some product orders, reduced demand on certain of its brands e-commerce sites, and delay of some wholesale shipments.
- The timing and amount of any insurance reimbursements are unknown.
Risks
- VF's ongoing assessment of the impacts of the cybersecurity incident could reveal additional information.
- There could be further delays in verifying all of VF's information technology systems.
- The incident could impact VF's relationships with customers, consumers, vendors, and employees.
- The company faces legal, reputational, and financial risks from the cybersecurity incident.
- Future cybersecurity incidents could result in unauthorized access to data, leading to claims, costs, and reputational harm.
- The effectiveness of cybersecurity remediation and recovery plans and cybersecurity risk management policies and practices is not guaranteed.
Future Outlook
VF will continue to assess the impacts of the cybersecurity incident and cooperate with law enforcement and regulatory authorities. The company will also seek reimbursement from its cybersecurity insurers. VF undertakes no obligation to publicly update or revise any forward-looking statements, whether as a result of new information, future events or otherwise, except as required by law.
Management Comments
- VF believes the threat actor was ejected from its IT systems on December 15, 2023.
- VF believes the material impact or reasonably likely material impact on VF is limited to the material impacts on VFs business operations disclosed in the Original Report which are no longer ongoing at this time.
- VF also believes the impacts of the cyber incident are not material and are not reasonably likely to be material to its financial condition and results of operations.
Industry Context
Cybersecurity incidents are a growing concern across all industries, and this event highlights the importance of robust security measures and incident response plans. The retail sector, with its large customer databases, is a frequent target for cyberattacks. This incident is similar to other recent breaches at major retailers, underscoring the need for continuous vigilance and investment in cybersecurity.
Comparison to Industry Standards
- The speed at which VF contained the incident, within two days, is relatively quick compared to some other companies that have experienced similar attacks.
- The disclosure of the number of affected consumers (35.5 million) is in line with industry best practices for transparency.
- The fact that VF does not store sensitive financial data like social security numbers and payment card information is a positive security measure, which is becoming more common in the industry.
- Other companies such as Target and Home Depot have experienced similar large-scale data breaches in the past, which resulted in significant financial and reputational damage. VF's response and the limited impact on its operations appear to be better than some of these past incidents.
Stakeholder Impact
- Shareholders may be concerned about the financial and reputational impact of the cyberattack.
- Consumers are impacted by the theft of their personal data.
- Employees may be affected by the operational disruptions and the need to address the incident.
- Vendors and suppliers may experience delays or disruptions in their dealings with VF.
Next Steps
- VF will continue its investigation into the cybersecurity incident.
- VF will cooperate with law enforcement and regulatory authorities.
- VF will seek reimbursement from its cybersecurity insurers.
- VF will continue to monitor its systems for any further issues.
Key Dates
| Date | Description |
|---|---|
| 2023-12-13 | VF detected unauthorized occurrences on its IT systems. |
| 2023-12-15 | VF believes the threat actor was ejected from its IT systems. |
| 2023-12-18 | VF filed the Original Report with the SEC. |
| 2024-01-18 | Date of this amended report. |
Keywords
cybersecurity, data breach, cyberattack, data theft, information technology, IT systems, personal data, incident response, retail, e-commerce, VF Corporation
Disclaimer:The information provided here is for general informational purposes only and does not constitute financial advice, recommendation, or endorsement of any kind. It may contain errors or omissions. You should not rely on this information to make financial decisions. Always seek the advice of a qualified financial professional before making any investment or financial decisions. Use of this information is at your own risk.