Retail is well and truly under attack. This isnโt new; retail has long been an attractive target for hackers, as cybercriminals always follow the money. The past few months, however, have seen numerous high-profile brands fall victim: Marks & Spencer, the Co-Op, Adidas and Victoriaโs Secret are all on that list. Now Cartier and The North Face can be added.
Itโs The North Face that interests me most because of the attack methodology. This wasnโt a ransomware attack. This wasnโt the exploitation of a zero-day vulnerability. It wasnโt, at least not directly, a social engineering attack. Nope, this was customers of The North Face quite literally getting stuffed by hackers.
According to the official data breach notification, The North Face detected suspicious activity on its website sometime on 23 April. The ensuing investigation quickly confirmed that โan attacker had launched a small-scale credential stuffing attackโ on its customers.
โBecause 81% of individuals reuse the same or similar passwords for multiple accounts,โ said Benjamin Fabre, CEO of DataDome, โmalicious threat actors with access to a list of leaked credentials have an easy time finding valid login and password combinations.โ
With access to the tools to enable automated password-stuffing attacks costing as little as ยฃ300, including the lists themselves and the proxy services to obfuscate the source, it’s little surprise that credential stuffing attacks are popular in cybercriminal circles.
โTodayโs automated credential cracking and credential stuffing tools are designed to check hundreds of thousands of credential combinations against multiple websites,โ Fabre explained.
Lessons to learn from The North Face attacks
But let’s focus on this attack against The North Face customer accounts. An attack that has left those affected facing the realisation that a hacker, and anyone they have shared the information with, now has access to the following details: products purchased, shipping address, email address, full name, date of birth and telephone number.
The North Face responded by enforcing a password reset across all accounts, and advised customers to use a unique password. You know, one that hasn’t been used anywhere else. The VF Corporation, which owns The North Face, has yet to respond to a request for further details regarding the attack.
Rob Ainscough, Chief Identity Security Advisor at Silverfort, warns that itโs the use of usernames and passwords to begin with that is creating an enormous and vulnerable attack surface.
โThe priority for retailers must be limiting the blast radius of a single compromised account,” said Ainscough. Retailers often focus on narrow compliance goals and operational efficiency in managing identity risk, he added, warning that the key should be to employ โidentity controls that can stop lateral movement in real-time and enforce MFA everywhereโ.
Although The North Face attack was against customer accounts, if similar techniques are used to compromise a staff account, the consequences amplify way beyond personal data breach.
Related articles