MACY'S, INC.
ent_019e5b5a98b4bb9064d03298f17eea96
Macy's is a major American department store chain that sells clothing, home furnishings, and beauty products through its physical stores and online platform.
AI-summarized from indexed web sources · New York, New York · 2026-08-04 · source
Disclosures
15
Leak Site · State AG · 8 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
162,507
nationwide · State AG OR
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- MACY'S, INC.
- Normalized
- macy s— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 529900NZQ81TIOW3CW52
- SEC EDGAR CIK
- 0000794367
- Domain
- macys.com
Disclosure history (15)newest first
- GLOBALLeak Siteas victim2025-11-21
Macy's.com is the online platform of Macy’s, Inc., one of the premier retailers in the United States. The company offers a range of products such as clothing, accessories, home goods and more from popular brands. It also provides features like online shopping, delivery, returns and customer service. Macy's.com reintroduces the convenience and ease of shopping to the customer's fingertips.
- California State AGas victim2019-11-15
macys.com experienced a data breach between October 7 and October 15, 2019, where an unauthorized third party injected malicious code into checkout and wallet pages to capture customer PII and payment card data. The incident was contained on October 15, 2019. Affected data included names, addresses, phone numbers, email addresses, payment card numbers, and security codes. Macy's engaged forensic investigators, notified law enforcement, reported card numbers to card brands, and provided 12 months of free identity protection services via Experian IdentityWorks.
- Oregon State AGas victim2019-11-15
macys.com reported a data breach to the Oregon Attorney General. The breach was reported on 2019-11-15. The breach occurred during 10/7/2019 - 10/15/2019. The breach was discovered on 10/15/2019. 135,152 individuals were affected. Notice was sent on 11/14/2019.
- Massachusetts State AGas victim2019-11-15
macys.com reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-11-15. 4,951 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2019-11-14
Macy's notified Montana residents of a data breach where unauthorized code was added to macys.com checkout and wallet pages between Oct 7-15, 2019. The code captured PII and payment card details. Macy's engaged forensic investigators, notified law enforcement and card brands, and offered 12 months of credit monitoring.
- Delaware State AGas victim2019-11-14
Macy's disclosed a data breach involving unauthorized access to macys.com. Between October 7 and October 15, 2019, an unauthorized third party injected malicious code into the checkout and wallet pages, capturing customer PII and payment card details. Macy's engaged law enforcement and forensic investigators, removed the code, and notified affected individuals, offering 12 months of credit monitoring.
- Washington State AGas victim2019-11-14
Macy's Inc. reported a cybersecurity incident in Washington where unauthorized code was added to macys.com checkout and wallet pages between Oct 7-15, 2019. The code captured PII and payment card data from 3,810 Washington residents. Macy's engaged forensic investigators, notified the FBI/Secret Service, and provided 12 months of Experian IdentityWorks services to affected individuals.
- Oregon State AGas victim2018-07-03
Macy's, Inc reported a data breach to the Oregon Attorney General. The breach was reported on 2018-07-03. The breach occurred during 5/26/2018 - 6/11/2018. The breach was discovered on 6/11/2018. 162,507 individuals were affected. Notice was sent on 6/19/20187/3/2018.
- Montana State AGas victim2018-07-02
Macy's, Inc. disclosed that an unauthorized third party used valid customer usernames and passwords to access online profiles between April 26 and June 12, 2018. The attacker accessed names, addresses, phone numbers, emails, birthdays, and payment card numbers. Macy's blocked affected profiles, reported card numbers to major networks, and offered 12 months of identity protection services.
- New Hampshire State AGas victim2018-07-02
Macy's, Inc. notified New Hampshire of a breach where attackers used stolen valid credentials to access customer profiles from April 26 to June 12, 2018. Discovered June 11, 2018. 753 NH residents affected. Data accessed included names, addresses, emails, phone numbers, birthdays, and attempted access to payment card data. Remediation included blocking profiles, purging card data, and offering 12 months of identity monitoring.
- Massachusetts State AGas victim2018-07-02
Macy's reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-07-02. 5,275 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2018-07-02
Macy's detected unauthorized access to customer online profiles on June 11, 2018, using valid usernames and passwords obtained from an external source. The unauthorized access occurred between April 26 and June 12, 2018. Affected data included names, addresses, phone numbers, email addresses, birthdays, and credit/debit card numbers with expiration dates. Macy's blocked affected profiles, reported card numbers to issuers, and offered 12 months of identity protection.
- Washington State AGas victim2018-07-01
Macy's, Inc. reported a cyberattack where an unauthorized third party used stolen valid credentials to access customer profiles on macys.com and bloomingdales.com. The incident occurred from April 26 to June 12, 2018, and was detected on June 11, 2018. The attacker accessed names, addresses, emails, phone numbers, and attempted to access payment card data. 3,564 Washington residents were notified.
- Massachusetts State AGas victim2012-12-18
Macy's reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2012-12-18. 10 Massachusetts residents were affected. The report records the breach type as paper.
- Massachusetts State AGas victim2009-03-02
Macy'c Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2009-03-02. 29 Massachusetts residents were affected. The report records the breach type as paper.