01Summary
In July 2024, the luxury retailer Neiman Marcus disclosed a data breach affecting 31.2 million customer accounts. The breach was claimed by the threat actor group Sp1d3rsHunters, who listed the stolen data for sale on a prominent hacking forum. The exposed data included customer names, addresses, email addresses, phone numbers, and limited payment card information. Neiman Marcus confirmed the breach and began notifying affected customers. The 31.2 million records significantly exceeded previous breaches at the company, representing a major security failure at the luxury retailer.
02Background
Neiman Marcus Group is a luxury department store chain operating Neiman Marcus, Bergdorf Goodman, and other brands. The company had previously suffered a data breach in 2014 affecting credit card data.
03Key revelations
- 01The breach was significantly larger than Neiman Marcus's 2014 breach.
- 02Customer data from a luxury retailer was being sold on hacking forums.
04Technical analysis
The specific attack vector was not publicly detailed. The volume of data (31.2M records) suggested comprehensive access to Neiman Marcus's customer database, likely through compromised credentials or web application exploitation.
- Attack vector
- Unknown (likely credential compromise or web app exploitation)
- Attack method
- Data exfiltration and extortion
- Exfiltration
- Database extraction
05Threat actor
Sp1d3rsHunters is a cybercriminal group known for targeting large enterprises, particularly in the retail and hospitality sectors. They operate a data extortion model, stealing data and demanding payment to prevent its sale or publication.
Aliases
- Sp1d3rsHunters3
Attribution sources
- Neiman Marcus Disclosure
- Threat Actor Claims
- Media Reports
06Victims and impact
Countries affected
- United States
07Data exposed
Data types
- Names
- Addresses
- Email Addresses
- Phone Numbers
- Payment Card Data (partial)
08Financial damage
Reputational damage, customer notification costs, potential regulatory fines.
09Timeline
- 2024-07-09Neiman Marcus discloses breach affecting 31.2M customer records.
10Reaction and fallout
Public reaction
Customers expressed frustration at the retailer's security practices, particularly given its previous 2014 breach.
11Legal
Multiple class-action lawsuits were filed.
Civil lawsuits
- Class-action lawsuits
12Aftermath
Security improvements
- Neiman Marcus implemented enhanced security measures.
13Significance and legacy
Significance
The 2024 Neiman Marcus breach was one of the largest retail sector breaches of the year, affecting over 31 million customers of a luxury brand.
Legacy
The incident underscored the persistent vulnerability of retail customer databases and the active market for stolen customer data.
14Disclosure and media
- Authentication
- Neiman Marcus disclosure
Publishing organisations
- Neiman Marcus Group
15Field notes
- 01The 2024 breach was significantly larger than Neiman Marcus's earlier 2014 breach.
- 02The data was listed for sale by Sp1d3rsHunters, a group known for targeting retail and hospitality sectors.
16Resolution
Neiman Marcus notified affected customers and worked with law enforcement.
17Sources
Official documents
- Neiman Marcus data breach notification
References
- [1]Neiman Marcus official disclosure
- [2]Media reports (BleepingComputer, The Record)









