Skip to content
cisonews.net

Incident · 8-K Item 1.05

VF Corporation reports encrypted systems and stolen data in the first Item 1.05 filing

Compiled 2026-09-27 from public records. By the cisonews.net Desk.

VF Corporation, the apparel group behind brands sold through its own stores and e-commerce sites, told investors on December 18, 2023 that it had detected unauthorized activity on part of its IT estate five days earlier. It filed the disclosure under Form 8-K Item 1.05 on the day that item took effect for most companies.

What the first filing said

VF dated its detection to December 13, 2023. The company said the intruder both encrypted systems and took information, including personal data. Stores stayed open, but order fulfilment from its brand websites was affected, and VF described the operational impact as material while recovery continued.

The January 2024 amendment

An 8-K/A filed on January 18, 2024 dated the removal of the intruder to December 15, 2023. It gave the first estimate of scale: personal data of approximately 35.5 million individual consumers. The amendment said VF does not keep consumer Social Security numbers, bank account details or payment card data in its direct-to-consumer systems, and that it no longer considered the incident material to its financial condition.

What the filings leave open

Neither filing names the threat actor or explains how it got in.

Sources

  1. 2023-12-18 · AVF Corporation, Form 8-K (SEC EDGAR), published December 18, 2023
  2. 2024-01-18 · AVF Corporation, Form 8-K/A (SEC EDGAR), published January 18, 2024

Tier A: the organization itself, a regulator or SEC EDGAR. Tier B: established press. Each fact on this page carries its supporting passage in the page source.

See an error? Corrections are made on the page and logged on the corrections page. Send them through contact.