Customer Data Breaches Confirmed at North Face and Cartier Amid Ongoing Cybercrime Surge
Luxury fashion brands The North Face and Cartier have disclosed recent cyberattacks that compromised customer data. North Face reported that a ‘small-scale’ breach occurred in April, involving credential stuffing—where attackers used login information from previous breaches to access accounts. Some users’ shipping addresses and purchase histories may have been accessed, though no financial information was stolen. VF Corporation, North Face’s parent company, had previously experienced a separate cyberattack in December 2023 affecting its Vans brand.
Cartier also confirmed that unauthorized actors briefly accessed their system, obtaining limited client information. The company stated that no passwords or payment details were compromised and that the incident has been contained, with improved system protections now in place. Both firms have notified affected customers and relevant authorities.
These attacks are part of a broader trend affecting major retailers, including Adidas, Victoria’s Secret, Harrods, M&S, and the Co-op. The UK’s National Crime Agency has prioritized investigating these cybercrimes. Experts highlight that retailers, rich in customer data, are increasingly attractive to cybercriminals who often exploit this information over time. These breaches underscore the persistent vulnerability of the retail sector in the face of evolving cybersecurity threats.
