Neiman Marcus confirmed a Snowflake-linked breach affecting 64,472 people
- Organization
- Neiman Marcus Group
- Exploit
- Credential Compromise
- Industry
- Retail
Neiman Marcus Group, which operates the Neiman Marcus and Bergdorf Goodman department store chains, disclosed in late June 2024 that an unauthorised third party had obtained customer data from a cloud database platform it used. The company identified the platform as one provided by Snowflake.
In breach notifications filed with the Maine and Vermont attorneys general, the retailer put the number of affected people at 64,472. The exposed fields varied by individual and included names, contact information, dates of birth and Neiman Marcus or Bergdorf Goodman gift card numbers. The company said gift card PINs were not included.
Neiman Marcus said the unauthorised access occurred between April and May 2024 and was discovered in May. It said it contained the incident by disabling access to the database platform and had engaged outside cybersecurity experts and notified law enforcement. The Record reported that the company did not offer identity theft protection services to those it notified.
The intrusion was one of a series against Snowflake customer accounts that also caught Ticketmaster and Santander. Snowflake's own systems were not breached; the attackers used credentials harvested by information-stealing malware. A seller using the alias Sp1d3r had offered the Neiman Marcus data on a cybercrime forum for $150,000 before the listing was removed, and claimed a far larger dataset than the company acknowledged.