HackingRetail & ConsumerRetailStolen CredentialsCapture Stored DataDelayed DiscoveryCustomer Data InvolvedData ExfiltratedIDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALSLowActive
The Neiman Marcus Group LLC
bd_64f1e5518aec51d7 · schema v1 · pii pii-v1
Full breach record for The Neiman Marcus Group LLC →In May 2020, an unauthorized party obtained personal information from Neiman Marcus Group customer online accounts. Affected data included names, contact information, payment card numbers and expiration dates (without CVV), virtual gift card numbers (without PIN), and online account credentials. The incident was discovered in early September 2021. NMG engaged a cybersecurity expert, notified law enforcement, and required password resets for affected accounts.
California clockDiscovered Sep 1, 2021 → Notified Sep 30, 202129d ✓ CA 60-day OK29 days discovery → filing
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_7461fbea0332a50aDelaware State AGfiled 2021-09-30Verified by operator
- bd_3a2af85b6cddd992Maine State AGfiled 2021-10-01(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-545944
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 30, 2021
- Raw hash
- 8b662aae642bcbd685a2274deea7cc53d521de120826298661f2ee2e83cbc7ff
Reporting entity
- Name
- The Neiman Marcus Group LLCnorm: the neiman marcus
Victim entity
- Name
- The Neiman Marcus Group LLCnorm: the neiman marcus
- Industry
- Retail & Consumerllm
Incident
- Discovered
- Sep 1, 2021
- Materiality determined
- —
- Notification sent
- Sep 30, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1530 Data from Cloud Storage ObjectT1589.001 Gather Victim Identity Information: Credentials
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 29 days(29 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 29d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 1, 2021→ Notified: Sep 30, 202129d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.