Skip to content
Data breachResolved

Neiman Marcus data breach (2024)

In 2024, the luxury retailer Neiman Marcus had data stolen from its Snowflake cloud environment via stolen credentials. The company reported about 64,000 individuals to regulators, but the leaked dataset exposed roughly 31 million unique email addresses along with names, contact details and gift-card numbers.

Victim
Neiman Marcus
records
31.2M
users
64.5K

In 2024, the U.S. luxury retailer Neiman Marcus โ€” which also operates Bergdorf Goodman โ€” had customer data stolen from a third-party Snowflake cloud database as part of the wider Snowflake credential-theft campaign that hit roughly 160 organizations. The company formally reported about 64,000 affected individuals to regulators, but the leaked dataset surfaced on a hacking forum exposing roughly 31 million unique email addresses.

What happened

Neiman Marcus stored customer data in Snowflake, a cloud data-warehouse platform. Beginning around 14 April 2024, attackers logged into the company's Snowflake instance using valid stolen credentials โ€” usernames and passwords harvested from earlier infostealer-malware infections, in many cases on personal or contractor devices. The targeted Snowflake accounts were not protected by multi-factor authentication, so a username and password alone were sufficient to authenticate.

The unauthorized access went undetected until around 24 May 2024. The intrusion was not a compromise of Snowflake's own platform but of customer-side credentials, a pattern repeated across dozens of Snowflake customers including Ticketmaster, Santander, AT&T and Advance Auto Parts.

Data exposed

According to the company's breach notification, the stolen information included:

  • Names and contact information
  • Email addresses and phone numbers
  • Dates of birth
  • Partial Social Security numbers and employee identification numbers (for a subset)
  • Neiman Marcus / Bergdorf Goodman gift-card numbers (without PINs)
  • Transaction data

Neiman Marcus reported 64,472 individuals to the Maine Attorney General's Office. However, when the dataset was independently analyzed after a threat actor put it up for sale, researchers found roughly 31 million unique email addresses โ€” the figure recorded by Have I Been Pwned at 31,152,842 records. The gap reflects the difference between individuals the company chose to formally notify and the total volume of records in the exfiltrated tables.

Threat actor and aftermath

A threat actor using the alias Sp1d3r claimed the breach and listed the data for sale on 27 June 2024. The activity is tied to the loose collective tracked as UNC5537 / ShinyHunters, which monetized the Snowflake campaign through extortion and forum sales. Neiman Marcus subsequently faced class-action litigation over its handling of the incident.

Why it matters

The Neiman Marcus breach is a representative case of the 2024 Snowflake campaign, where the root cause was not a vendor zero-day but credential reuse and missing MFA on cloud data-warehouse accounts. It also highlights a recurring disclosure-scope mismatch: the ~64,000 figure reported to regulators sat far below the ~31 million email addresses actually present in the leaked data, a discrepancy that fueled both litigation and public scrutiny.

Timeline

  1. Attackers begin accessing Neiman Marcus data stored in a third-party Snowflake cloud environment using stolen credentials.

  2. The unauthorized access is detected, ending the intrusion window.

  3. Neiman Marcus begins notifying affected individuals and files with the Maine Attorney General, reporting 64,472 people.

  4. A threat actor using the alias Sp1d3r offers the stolen Neiman Marcus database for sale on a hacking forum.

  5. Sp1d3r/ShinyHunters-linked actors leak databases tied to multiple Snowflake-customer victims.

Sources

  1. haveibeenpwned.comhttps://haveibeenpwned.com/PwnedWebsites#NeimanMarcus
  2. bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/neiman-marcus-confirms-data-breach-after-snowflake-account-hack/
  3. bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/neiman-marcus-data-breach-31-million-email-addresses-found-exposed/
  4. therecord.mediahttps://therecord.media/neiman-marcus-snowflake-breach-thousands
  5. en.wikipedia.orghttps://en.wikipedia.org/wiki/Snowflake_data_breach

Related incidents

Data breachResolved

Under Armour data breach (2025)

In November 2025, the Everest ransomware group claimed to have stolen 343GB of data from apparel maker Under Armour. After no ransom was paid, customer data was leaked in January 2026, exposing roughly 72.7 million unique email addresses with names, dates of birth, genders, locations and purchase histories. This is a separate incident from the 2018 MyFitnessPal breach.

Victim
Under Armour
Records
72.7M
Data breachResolved

Famm data breach (2020)

In late 2020, the Japanese family photos website Famm suffered a data breach that subsequently exposed 1.3M customer records, including 535k unique email addresses. Impacted data also included names, dates of birth, genders and passwords stored as SHA-256 hashes.

Victim
Famm
Records
535.2K
Data breachResolved

Zynga data breach (2019)

In September 2019, the hacker Gnosticplayers breached game developer Zynga, accessing data for nearly 173 million Words With Friends and Draw Something players. Exposed data included emails, usernames, phone numbers, and salted SHA-1 password hashes.

Victim
Zynga
Records
172.9M