- The North Face, Cartier, and other big-name retailers have been hit by cyber attacks in recent weeks.
- Most were caused by credential stuffing – an avoidable, preventable attack method.
- SMBs face similar risks but have fewer resources to recover.
- Here’s what your business can learn – and how to take action now.
Fashion giant The North Face and luxury jeweller Cartier have become the latest in a growing list of high-profile brands to fall victim to cyberattacks – highlighting serious gaps in retail cyber security and lessons for every business, regardless of size.
The North Face confirmed a “small-scale” credential stuffing attack in April 2025, marking the fourth such breach the company has faced since 2020.
While the company claims that no financial data was accessed, affected customers were notified that personal data – including names, email addresses, shipping addresses, and purchase histories – may have been compromised. Users are being urged to change their passwords, though many are questioning why protections like MFA weren’t already mandatory.
The Method: Credential Stuffing
According to The North Face, the attackers employed credential stuffing – a method where stolen usernames and passwords from prior breaches are reused in automated attempts to access accounts elsewhere. This method exploits one of the most common security lapses among users: password reuse.
Not an Isolated Incident
Cartier, the renowned luxury brand, was also breached in a separate incident where an “unauthorised party gained temporary access” to its systems. Though passwords and card details were reportedly safe, limited client data was exposed. In a customer email send to customers, Cartier assured recipients that the breach was contained and authorities had been notified.
These breaches are part of a larger pattern. In the last few weeks alone, the retail sector has seen cyberattacks on Adidas, Victoria’s Secret, Harrods, Co-op, and Marks & Spencer (M&S). The latter estimates the disruption could cost up to £300 million this year, with online services impacted until July.
Victoria’s Secret even had to take down its US website following a “security incident,” while the Co-op faced supply chain breakdowns that led to empty shelves in stores.
A Sector – and Strategy – Under Pressure
Retailers are prime targets for cybercriminals – not just because of the volume of customer data they hold, but due to often inconsistent levels of cybersecurity maturity. The UK’s National Crime Agency has stated that tracking down the attackers responsible for this wave of incidents is now a “top priority.”
From a business continuity and brand trust standpoint, the impact is profound. While some companies downplay the significance of exposed “non-financial” data, these details – when cross-referenced – can fuel identity theft, phishing attacks, and further intrusions.
The bigger picture? If these companies – with dedicated IT teams – are still vulnerable, it’s time for SMBs to seriously re-evaluate their own defences.
What SMBs Can Do Now
If major global retailers are vulnerable, what can small to medium-sized businesses (SMBs) do to protect themselves? The answer lies in focus, education, and proactive security strategy.
1. Enforce MFA Across the Board
Credential stuffing thrives when companies rely solely on passwords. MFA can stop these attacks in their tracks. For businesses of any size, implementing MFA for both staff and customer portals is one of the most cost-effective defences available.
2. Monitor for Unusual Activity
Automated tools can detect suspicious login behaviour, geographic anomalies, or signs of credential stuffing. These solutions are increasingly accessible – even to smaller businesses – and can offer critical early warnings.
3. Educate Users and Staff
Security awareness isn’t just for IT teams. Train staff on phishing red flags, proper password hygiene, and best practices for data handling. Even small teams benefit enormously from periodic training.
4. Create a Response Plan
When a breach happens, response time is critical. Prepare a clear incident response plan that outlines steps, responsibilities, and communications. Test it periodically to ensure everyone knows what to do.
5. Review Third-Party Risk
As in the case of VF Corporation’s earlier breach (affecting another of its brands, Vans), supply chain or third-party exposures can also lead to compromise. SMBs must assess the security of partners, platforms, and vendors they rely on.
6. Talk to Experts
Cyber security is too complex and fast-moving to navigate alone – especially for SMBs juggling multiple responsibilities. Consulting with experienced IT security partners like Dr Logic can provide tailored guidance that goes beyond generic advice. Whether it’s stress-testing your defences, implementing zero-trust architectures, or creating a realistic cybersecurity roadmap, expert insight ensures you’re prioritising the right measures for your business size, sector, and risk profile. It’s not about buying more tools – it’s about making smarter decisions.
Final Thoughts: Retail or Not, The Risks Are Shared
These incidents aren’t confined to global fashion labels. They reflect a wider issue in cyber security: the assumption that “basic” attacks like password stuffing don’t merit attention. They do – especially when they repeatedly succeed.
For SMBs, now is the time to reassess. The cost of inaction is growing. From reputational damage to operational downtime and customer churn, the risks are too significant to ignore.
Cybersecurity may not be glamorous, but in 2025, it’s the new cost of doing business.
Need help identifying your weak spots?
Book a free cyber security consultation with Dr Logic to explore practical, budget-friendly ways to reduce risk – without overcomplicating your IT setup.



















































