VF Corporation said a December 2023 cyberattack involved the theft of personal data associated with approximately 35.5 million consumers. That is VF’s preliminary estimate in a January 18, 2024 SEC filing—not a final independently verified count. The filing does not identify the data fields stolen or establish whether any particular Vans customer was affected.
What happened at VF Corporation?
VF Corporation, the apparel company that owns Vans, said it detected unauthorized activity on some of its IT systems on December 13, 2023. The company activated its incident response plan, brought in external cybersecurity experts, began containment and remediation, and shut down some systems. VF said it believed the threat actor had been ejected by December 15, while its investigation and remediation continued. VF Corporation’s January 18, 2024 Form 8-K/A reported the incident and its preliminary findings.
In that filing, VF estimated that personal data associated with approximately 35.5 million individual consumers had been stolen. The figure belongs to VF and to its preliminary analysis as of the filing date; it should not be treated as a finalized tally.
What information was stolen?
VF’s filing says “personal data,” but does not name the specific fields involved. It therefore does not establish whether names, contact details, dates of birth, or other particular information was taken.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
VF said its direct-to-consumer IT systems did not retain consumer Social Security numbers, bank account information, or payment-card information. It also said it had not detected evidence at that time that consumer passwords were acquired. Those statements are limited to the direct-to-consumer systems and the company’s findings at the time; they do not establish what every VF system or customer channel contained, or what all categories of data were affected.
Can Vans customers tell whether their data was affected?
Not from VF’s public filing alone. The company reported an aggregate estimate, not a list of affected individuals, and the filing does not say which consumers were included. It also does not establish which jurisdictions were affected, who received individual notice, or whether VF offered monitoring. The sources cited here do not resolve those questions.
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
If you received a notice that appears to be from VF or one of its brands, verify it through an official company channel rather than relying on links or phone numbers in an unexpected message. Do not assume that a message is genuine—or that you were affected—based only on the 35.5 million estimate.
Did the incident disrupt orders or retail operations?
VF reported impacts to inventory replenishment, order fulfillment, e-commerce demand, and wholesale shipments. In its January 2024 filing, the company said orders had been caught up and systems were substantially restored, although minor operational impacts remained. The filing’s operational update describes recovery at that time; it does not change what is known about the stolen data.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Rank #3
What does VF’s later filing add?
VF’s fiscal 2026 annual filing refers to the December 2023 incident in its wider discussion of cybersecurity risks, including possible operational, reputational, legal, and regulatory consequences. That retrospective risk discussion is not evidence that new consumer data was exposed or that the estimated count changed. VF’s fiscal 2026 annual filing provides that broader company context.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Why did VF disclose the incident in an SEC filing?
SEC staff guidance says a public company must file Form 8-K Item 1.05 within four business days after determining a cybersecurity incident is material, subject to a specified process for delaying disclosure in certain national-security or public-safety circumstances. This is an issuer-disclosure rule, not a deadline for notifying individual consumers. The SEC staff’s December 14, 2023 guidance explains the filing requirement.
Quick Recap
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




