macys.com
ent_186bcaa712928727
Disclosures
4
Leak Site · State AG · 4 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
135,152
as filed · State AG OR
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- macys.com
- Normalized
- macyscom— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- macys.com
Disclosure history (4)newest first
- GLOBALLeak Siteas victim2025-11-21
Macy's.com is the online platform of Macy’s, Inc., one of the premier retailers in the United States. The company offers a range of products such as clothing, accessories, home goods and more from popular brands. It also provides features like online shopping, delivery, returns and customer service. Macy's.com reintroduces the convenience and ease of shopping to the customer's fingertips.
- 🐻California State AGas victim2019-11-15
macys.com experienced a data breach between October 7 and October 15, 2019, where an unauthorized third party injected malicious code into checkout and wallet pages to capture customer PII and payment card data. The incident was contained on October 15, 2019. Affected data included names, addresses, phone numbers, email addresses, payment card numbers, and security codes. Macy's engaged forensic investigators, notified law enforcement, reported card numbers to card brands, and provided 12 months of free identity protection services via Experian IdentityWorks.
- 🦫Oregon State AGas victim2019-11-15
macys.com reported a data breach to the Oregon Attorney General. The breach was reported on 2019-11-15. The breach occurred during 10/7/2019 - 10/15/2019. The breach was discovered on 10/15/2019. 135,152 individuals were affected. Notice was sent on 11/14/2019.
- 💎Delaware State AGas victim2019-11-14
Macy's disclosed a data breach involving unauthorized access to macys.com. Between October 7 and October 15, 2019, an unauthorized third party injected malicious code into the checkout and wallet pages, capturing customer PII and payment card details. Macy's engaged law enforcement and forensic investigators, removed the code, and notified affected individuals, offering 12 months of credit monitoring.