HackingStolen CredentialsCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALSMediumActive
The Neiman Marcus Group LLC
bd_7461fbea0332a50a · schema v1 · pii pii-v1
Full breach record for The Neiman Marcus Group LLC →The Neiman Marcus Group notified customers of a data breach involving unauthorized access to online account information in May 2020. Affected data included names, contact info, payment card numbers (no CVV), virtual gift card numbers, and usernames/passwords/security questions. The company engaged cybersecurity experts and law enforcement, and required password resets for affected accounts. The investigation was ongoing as of the September 30, 2021 notification.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_64f1e5518aec51d7California State AGfiled 2021-09-30Candidate
- bd_3a2af85b6cddd992Maine State AGfiled 2021-10-01(1d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2021/10/NMG-Email-Notification-Letter.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 30, 2021
- Raw hash
- 8148d779ab037fe32954a815d7ed91821762723840cc0318bacf56bb00fa8a46
Reporting entity
- Name
- The Neiman Marcus Group LLCnorm: the neiman marcus
- Domain
- neimanmarcus.com
Victim entity
- Name
- The Neiman Marcus Group LLCnorm: the neiman marcus
- Domain
- neimanmarcus.com
Incident
- Discovered
- May 1, 2021
- Materiality determined
- —
- Notification sent
- Sep 30, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 22 weeks(152 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.