How customers of The North Face got stuffed by hackers – quite literally

Retail is well and truly under attack. This isnโ€™t new; retail has long been an attractive target for hackers, as cybercriminals always follow the money. The past few months, however, have seen numerous high-profile brands fall victim: Marks & Spencer, the Co-Op, Adidas and Victoriaโ€™s Secret are all on that list. Now Cartier and The North Face can be added.

Itโ€™s The North Face that interests me most because of the attack methodology. This wasnโ€™t a ransomware attack. This wasnโ€™t the exploitation of a zero-day vulnerability. It wasnโ€™t, at least not directly, a social engineering attack. Nope, this was customers of The North Face quite literally getting stuffed by hackers.

According to the official data breach notification, The North Face detected suspicious activity on its website sometime on 23 April. The ensuing investigation quickly confirmed that โ€œan attacker had launched a small-scale credential stuffing attackโ€ on its customers.

โ€œBecause 81% of individuals reuse the same or similar passwords for multiple accounts,โ€ said Benjamin Fabre, CEO of DataDome, โ€œmalicious threat actors with access to a list of leaked credentials have an easy time finding valid login and password combinations.โ€

With access to the tools to enable automated password-stuffing attacks costing as little as ยฃ300, including the lists themselves and the proxy services to obfuscate the source, it’s little surprise that credential stuffing attacks are popular in cybercriminal circles.

โ€œTodayโ€™s automated credential cracking and credential stuffing tools are designed to check hundreds of thousands of credential combinations against multiple websites,โ€ Fabre explained.

Lessons to learn from The North Face attacks

But let’s focus on this attack against The North Face customer accounts. An attack that has left those affected facing the realisation that a hacker, and anyone they have shared the information with, now has access to the following details: products purchased, shipping address, email address, full name, date of birth and telephone number.

The North Face responded by enforcing a password reset across all accounts, and advised customers to use a unique password. You know, one that hasn’t been used anywhere else. The VF Corporation, which owns The North Face, has yet to respond to a request for further details regarding the attack.

Rob Ainscough, Chief Identity Security Advisor at Silverfort, warns that itโ€™s the use of usernames and passwords to begin with that is creating an enormous and vulnerable attack surface.

โ€œThe priority for retailers must be limiting the blast radius of a single compromised account,” said Ainscough. Retailers often focus on narrow compliance goals and operational efficiency in managing identity risk, he added, warning that the key should be to employ โ€œidentity controls that can stop lateral movement in real-time and enforce MFA everywhereโ€.

Although The North Face attack was against customer accounts, if similar techniques are used to compromise a staff account, the consequences amplify way beyond personal data breach.

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.