Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Incident Response

Neiman Marcus Confirms Payment Cards Compromised in Data Breach

Luxury retail company Neiman Marcus Group on Thursday confirmed that customer information was indeed stolen in a data breach.

During the incident, which occurred in May 2020, hackers were able to exfiltrate information associated with online customer accounts, including payment card data, the company says.

Luxury retail company Neiman Marcus Group on Thursday confirmed that customer information was indeed stolen in a data breach.

During the incident, which occurred in May 2020, hackers were able to exfiltrate information associated with online customer accounts, including payment card data, the company says.

A total of 4.6 million online customers were affected by the attack and Neiman Marcus is working on notifying them. The company also says that 3.1 million payment and virtual gift cards were compromised, 85% of which were either expired or invalid.

Personal information stolen in the attack includes names and contact information, usernames, passwords, as well as answers to security questions associated with the online accounts.

The attackers, the company says, were able to steal payment card numbers and expiration dates, but not associated CVV numbers. For the affected Neiman Marcus virtual gift card numbers, PINs were not compromised.

“No active Neiman Marcus-branded credit cards were impacted. At this time, the Company has no evidence that Bergdorf Goodman or Horchow online customer accounts were affected,” Neiman Marcus said.

Advertisement. Scroll to continue reading.

The company notes that it has also prompted users to change their passwords, provided they did not do so since May 2020.

“We are working hard to support our customers and answer questions about their online accounts. We will continue to take actions to enhance our system security and safeguard information,” said Geoffroy van Raemdonck, the CEO of Neiman Marcus Group.

Related: Controversial Web Host Epik Confirms Customer Data Exposed in Breach

Related: UK Minister Sorry Over Afghan Interpreters’ Data Breach

Related: IBM: Average Cost of Data Breach Exceeds $4.2 Million

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more.

Register

This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.

Register

People on the Move

Fable Security has appointed Jacob Berry as Chief Information Security Officer.

iCOUNTER has named Ali Waezzadah as Chief Information Security Officer.

Roger Hale has joined 1Kosmos as Chief Information Security Officer.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.