Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Incident Response

Neiman Marcus Confirms Payment Cards Compromised in Data Breach

Luxury retail company Neiman Marcus Group on Thursday confirmed that customer information was indeed stolen in a data breach.

During the incident, which occurred in May 2020, hackers were able to exfiltrate information associated with online customer accounts, including payment card data, the company says.

Luxury retail company Neiman Marcus Group on Thursday confirmed that customer information was indeed stolen in a data breach.

During the incident, which occurred in May 2020, hackers were able to exfiltrate information associated with online customer accounts, including payment card data, the company says.

A total of 4.6 million online customers were affected by the attack and Neiman Marcus is working on notifying them. The company also says that 3.1 million payment and virtual gift cards were compromised, 85% of which were either expired or invalid.

Personal information stolen in the attack includes names and contact information, usernames, passwords, as well as answers to security questions associated with the online accounts.

The attackers, the company says, were able to steal payment card numbers and expiration dates, but not associated CVV numbers. For the affected Neiman Marcus virtual gift card numbers, PINs were not compromised.

“No active Neiman Marcus-branded credit cards were impacted. At this time, the Company has no evidence that Bergdorf Goodman or Horchow online customer accounts were affected,” Neiman Marcus said.

The company notes that it has also prompted users to change their passwords, provided they did not do so since May 2020.

“We are working hard to support our customers and answer questions about their online accounts. We will continue to take actions to enhance our system security and safeguard information,” said Geoffroy van Raemdonck, the CEO of Neiman Marcus Group.

Advertisement. Scroll to continue reading.

Related: Controversial Web Host Epik Confirms Customer Data Exposed in Breach

Related: UK Minister Sorry Over Afghan Interpreters’ Data Breach

Related: IBM: Average Cost of Data Breach Exceeds $4.2 Million

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

Professional services company Slalom has appointed Christopher Burger as its first CISO.

More People On The Move

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

CISO Strategy

SecurityWeek spoke with more than 300 cybersecurity experts to see what is bubbling beneath the surface, and examine how those evolving threats will present...

CISO Conversations

Joanna Burkey, CISO at HP, and Kevin Cross, CISO at Dell, discuss how the role of a CISO is different for a multinational corporation...

CISO Conversations

In this issue of CISO Conversations we talk to two CISOs about solving the CISO/CIO conflict by combining the roles under one person.

CISO Strategy

Security professionals understand the need for resilience in their company’s security posture, but often fail to build their own psychological resilience to stress.

Data Breaches

LastPass DevOp engineer's home computer hacked and implanted with keylogging malware as part of a sustained cyberattack that exfiltrated corporate data from the cloud...