Skip to content
VF · SEC 8-K Item 1.05Filed Dec 18, 2023

VF discloses a material cybersecurity incident

Material cybersecurity incidentSecurityUpdated 20h ago
Disclosed
Dec 18, 2023
Records
Not stated
Industry
Manufacturing
Filings
2
Data involved
Not listed by the filing.
SEC filing

What the filing says

On December 13, 2023, VF Corporation ("VF" or the "Company") detected unauthorized occurrences on a portion of its information technology (IT) systems. Upon detecting the unauthorized occurrences, the Company immediately began taking steps to contain, assess and remediate the incident, including beginning an investigation with leading external cybersecurity experts, activating its incident response plan, and shutting down some systems. The threat actor disrupted the Company's business operations by encrypting some IT systems, and stole data from the Company, including personal data.

Timeline

  1. Amended filing · Jan 18, 00:00 UTC
    8-K/A: As disclosed in the Original Report, on December 13, 2023, VF detected unauthorized occurrences on a portion of its information technology (IT) systems. Upon detecting the unauthorized occurrences, VF immediately began taking steps to contain, assess and remediate the cyber incident, including beginning an investigation with leading external cybersecurity experts, activating its incident response plan, and shutting down some systems. As a result of these and other measures, and while VF's investigation and remediation efforts remain ongoing, VF believes the threat actor was ejected from VF's IT systems on December 15, 2023.

From vendors' own status pages and disclosures. Times as reported. Logos via logo.dev; trademarks belong to their owners.

Weekly: the week's major outages, postmortems and breaches, Saturday mornings.