Breach report
RetailNeiman Marcus
Neiman Marcus data breach: 31 million email addresses found exposed
Luxury retailer Neiman Marcus told regulators that about 64,000 people were affected by a Snowflake-related breach, but Have I Been Pwned found more than 31 million unique email addresses in the stolen data offered for sale online.
Reported by BleepingComputer
Records exposed
31.2M
31 million unique email addresses (company notified 64,472 people)
Scale vs. largest on file
- When
- 2024
- How they got in
- Stolen credentials to Snowflake cloud database without multifactor authentication
- Sector
- Retail
In June 2024, Neiman Marcus Group, the owner of the Neiman Marcus and Bergdorf Goodman department stores, disclosed that an unauthorized party had gained access to a cloud database platform provided by Snowflake. In a filing with the Maine attorney general, the luxury retailer said the intrusion took place in April and May 2024 and affected 64,472 people. The exposed data included names, contact details, dates of birth and gift card numbers without PINs.
The breach was part of the broader 2024 campaign in which a financially motivated group, tracked by Mandiant as UNC5537, logged into roughly 165 organizations' Snowflake accounts using credentials stolen by infostealer malware, many of them years old, from accounts that lacked multifactor authentication. Other victims included Ticketmaster, Santander, AT&T and Advance Auto Parts. Snowflake's own platform was not breached; the attackers simply signed in as legitimate users and exported data in bulk, which made the thefts hard to distinguish from normal activity.
Weeks before the company's disclosure, a hacker using the alias Sp1d3r had advertised Neiman Marcus data for $150,000 on a hacking forum, claiming it included 70 million transactions with customer details, 12 million gift card numbers, partial Social Security numbers, shopping records and employee data. In 2024, Troy Hunt of Have I Been Pwned analyzed the dataset and found 31,152,842 unique email addresses, far exceeding the number of people the retailer had formally notified.
The discrepancy highlighted a recurring gap in breach disclosure: companies often notify only customers whose most sensitive data, such as Social Security numbers, is confirmed exposed, while far larger sets of contact and purchase data go unreported under state law thresholds. Neiman Marcus offered affected customers identity protection services, and class action lawsuits were filed alleging it failed to secure customer data and to notify all those affected.
The incident showed how a single missing safeguard on a cloud account can put a luxury retailer's entire customer database at risk, and how affluent shoppers' data is especially valuable for targeted fraud. For businesses, it reinforced the need to enforce multifactor authentication, restrict network access to data warehouses and rotate old credentials. For consumers, it was a reminder that the official notification count may understate how widely their information has spread.