News: 1705672612

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Thieves steal 35.5M customers’ data from Vans sneakers maker

(2024/01/19)


VF Corporation, parent company of clothes and footwear brands including Vans and North Face, says 35.5 million customers were impacted in some way when criminals broke into their systems in December.

The announcement was made in a Thursday 8-K/A filing with the Securities and Exchange Commission (SEC), and we're only left to speculate about what kind of information the attackers may have scrambled away with.

The parent company of fashion labels, which also include Supreme, Timberland, and Dickies did, however, confirm the type of data that couldn't have been accessed.

[1]

VF Corp said that customers' social security numbers (SSNs), bank account information, and payment card information remain uncompromised as these are not stored in its IT systems.

[2]

[3]

There's also no evidence to suggest that consumer passwords were accessed, it confirmed, although it did caveat this with "the investigation remains ongoing".

If you want to really look between the lines of the document's wording, you'll see that VF Corp explicitly said SSNs, financial information, and passwords – all excluded from potential compromise – were all explicitly defined as being consumer-related specifically.

[4]

The same goes for the number of individuals affected – 35.5 million "individual consumers" had their personal information stolen.

Neither its original breach disclosure filing nor this week's update mentioned compromised data related to staff, business partners, or other stakeholders. The Register requested a statement from VF Corp but had not received a response by the time of publishing.

As for the operational disruption the attack caused, VF Corp said IT systems have been "substantially restored" and its businesses are now operating with minimal disruption.

[5]

When the attack was [6]first disclosed , the clothes seller said its ability to fulfill orders was affected, but online and retail stores were still up and running as normal.

[7]IT consultant fined for daring to expose shoddy security

[8]JPMorgan exec claims bank repels 45 billion cyberattack attempts per day

[9]Future of America's Cyber Safety Review Board hangs in balance amid calls for rethink

[10]Ransomware attacks hospitalizing security pros, as one admits suicidal feelings

This week's filing said the company's ability to replenish retail stores' inventory was affected and combined with the fulfillment issues. This led to customer order cancellations and reduced demand across some of its brands' e-commerce sites.

"Since the filing of the original report, while VF is still experiencing minor residual impacts from the cyber incident, VF has resumed retail store inventory replenishment and product order fulfillment, and is caught up on fulfilling orders that were delayed as a result of the cyber incident," the [11]filing reads.

"Since the filing of the original report, VF has substantially restored the IT systems and data that were impacted by the cyber incident, but continues to work through minor operational impacts."

The attack on VF Corp is suspected to have involved ransomware. The filings mention parts of its IT systems being encrypted, and the [12]AlphV/BlackCat gang claimed the attack days after its disclosure, but the company has not confirmed this to be the case.

That being said, it wouldn't be the first ransomware victim to carefully massage the wording of its disclosures so as to avoid the dreaded R word.

The practice is commonplace in the industry and reached its peak last year when Minneapolis Public Schools notoriously referred to its attack, later claimed by the Medusa ransomware gang, as an "encryption event." ®

Get our [13]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZaqqvjoFZTNmWSs9I6I2RwAAAA8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZaqqvjoFZTNmWSs9I6I2RwAAAA8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZaqqvjoFZTNmWSs9I6I2RwAAAA8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZaqqvjoFZTNmWSs9I6I2RwAAAA8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZaqqvjoFZTNmWSs9I6I2RwAAAA8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2023/12/18/vf_vans_cybersecurity_incident/

[7] https://www.theregister.com/2024/01/19/germany_fine_security/

[8] https://www.theregister.com/2024/01/18/jpmorgan_exec_attacks/

[9] https://www.theregister.com/2024/01/18/cyber_safety_review_board_rethink/

[10] https://www.theregister.com/2024/01/18/ransomware_attacks_hospitalize_security_pros/

[11] https://www.sec.gov/ix?doc=/Archives/edgar/data/103379/000119312524010243/d641969d8ka.htm

[12] https://www.theregister.com/2023/12/19/blackcat_domain_seizure/

[13] https://whitepapers.theregister.com/



Why do they need customers' SSN?

Colin Miller

What legitimate reason does a webstore need for its customers' SSN number?

Postal and email address, yes. Credit card numbers ideally should be kept on a different server, and passwords should be salted.

But I can see no reason for the SSN, nor what they would do with it

Re: Why do they need customers' SSN?

Catkin

SSN is a good way to uniquely identify US residents without the pitfalls of things like the birthday paradox and culturally common names. The problem is that it's grown legs and become a form of ID verification, which is terrible. Because of said leg growing, it's a bad idea for it to be held by a shop but, in the long term, businesses need to move away from using it as a verification code.

Re: Why do they need customers' SSN?

Mike 137

" Credit card numbers ideally should be kept on a different server "

Whether on a different server or not, credit card numbers (PANs) should ideally not be stored at all once any given transaction is completed. If they must be stored beyond this, PCI-DSS requires that they be one way hashed or truncated (but not both), strongly encrypted with adequate key management, or tokenised. The aim, of course, is to make the PAN unreadable so it doesn't matter if it's leaked.

"Oops," Says MPAA President

Recently, the United States filed a legal brief in support of the MPAA's
argument that linking to the DeCSS source code is not protected by the
First Amendment.

At the time, the MPAA was ecstatic. But not any longer. The tables have
turned: the Federal government has filed a lawsuit against the movie
industry, arguing that many Hollywood-produced movies 'link' to illegal
content. The MPAA is now desperately wrapping itself up in the Bill of
Rights.

"Murder is illegal. Showing a murder in a movie -- or, rather, 'linking'
to it -- is also illegal," explained a spokesperson for the Coalition Of
Angry Soccer Moms In Support Of Brow-Beating Movie Industry Executives, an
interest group that has backed the government's lawsuit.