https://www.bleepingcomputer.com/news/security/the-north-face-warns-customers-of-april-credential-stuffing-attack/
Outdoor apparel retailer The North Face is warning customers that their personal information was stolen in credential stuffing attacks targeting the company’s website in April. … The data that has been exposed includes the following:
- Full name
- Purchase history
- Shipping address
- Email address
- Date of birth
- Telephone number …
BleepingComputer notes North Face doesn’t enforce MFA, and this is the 4th credential stuffing incident since 2020.
Regards