Neiman Marcus data breach (2024)
In 2024, the luxury retailer Neiman Marcus had data stolen from its Snowflake cloud environment via stolen credentials. The company reported about 64,000 individuals to regulators, but the leaked dataset exposed roughly 31 million unique email addresses along with names, contact details and gift-card numbers.
- Victim
- Neiman Marcus
- records
- 31.2M
- users
- 64.5K
In 2024, the U.S. luxury retailer Neiman Marcus โ which also operates Bergdorf Goodman โ had customer data stolen from a third-party Snowflake cloud database as part of the wider Snowflake credential-theft campaign that hit roughly 160 organizations. The company formally reported about 64,000 affected individuals to regulators, but the leaked dataset surfaced on a hacking forum exposing roughly 31 million unique email addresses.
What happened
Neiman Marcus stored customer data in Snowflake, a cloud data-warehouse platform. Beginning around 14 April 2024, attackers logged into the company's Snowflake instance using valid stolen credentials โ usernames and passwords harvested from earlier infostealer-malware infections, in many cases on personal or contractor devices. The targeted Snowflake accounts were not protected by multi-factor authentication, so a username and password alone were sufficient to authenticate.
The unauthorized access went undetected until around 24 May 2024. The intrusion was not a compromise of Snowflake's own platform but of customer-side credentials, a pattern repeated across dozens of Snowflake customers including Ticketmaster, Santander, AT&T and Advance Auto Parts.
Data exposed
According to the company's breach notification, the stolen information included:
- Names and contact information
- Email addresses and phone numbers
- Dates of birth
- Partial Social Security numbers and employee identification numbers (for a subset)
- Neiman Marcus / Bergdorf Goodman gift-card numbers (without PINs)
- Transaction data
Neiman Marcus reported 64,472 individuals to the Maine Attorney General's Office. However, when the dataset was independently analyzed after a threat actor put it up for sale, researchers found roughly 31 million unique email addresses โ the figure recorded by Have I Been Pwned at 31,152,842 records. The gap reflects the difference between individuals the company chose to formally notify and the total volume of records in the exfiltrated tables.
Threat actor and aftermath
A threat actor using the alias Sp1d3r claimed the breach and listed the data for sale on 27 June 2024. The activity is tied to the loose collective tracked as UNC5537 / ShinyHunters, which monetized the Snowflake campaign through extortion and forum sales. Neiman Marcus subsequently faced class-action litigation over its handling of the incident.
Why it matters
The Neiman Marcus breach is a representative case of the 2024 Snowflake campaign, where the root cause was not a vendor zero-day but credential reuse and missing MFA on cloud data-warehouse accounts. It also highlights a recurring disclosure-scope mismatch: the ~64,000 figure reported to regulators sat far below the ~31 million email addresses actually present in the leaked data, a discrepancy that fueled both litigation and public scrutiny.
Timeline
Attackers begin accessing Neiman Marcus data stored in a third-party Snowflake cloud environment using stolen credentials.
The unauthorized access is detected, ending the intrusion window.
Neiman Marcus begins notifying affected individuals and files with the Maine Attorney General, reporting 64,472 people.
A threat actor using the alias Sp1d3r offers the stolen Neiman Marcus database for sale on a hacking forum.
Sp1d3r/ShinyHunters-linked actors leak databases tied to multiple Snowflake-customer victims.
Sources
- haveibeenpwned.comhttps://haveibeenpwned.com/PwnedWebsites#NeimanMarcus
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/neiman-marcus-confirms-data-breach-after-snowflake-account-hack/
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/neiman-marcus-data-breach-31-million-email-addresses-found-exposed/
- therecord.mediahttps://therecord.media/neiman-marcus-snowflake-breach-thousands
- en.wikipedia.orghttps://en.wikipedia.org/wiki/Snowflake_data_breach