Clustered 3 filings across 3 jurisdictions · filing window Sep 30, 2021 → Oct 1, 2021. View entity profile → Other incidents for this victim →
incident inc_58f91732c645484b · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Identity (basic) · Financial account · Credentials
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
CA DE ME
all State AG
Earliest sighting first · deep chronology in Litigation Timeline
May 2, 2020 → May 17, 2020
When the intrusion reportedly occurred, per the linked filings
May 1, 2021
Reported by DELAWARE AG filing
Sep 1, 2021
Reported by CALIFORNIA AG filing
Sep 9, 2021
Reported by MAINE AG filing
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
In May 2020, an unauthorized party obtained personal information from Neiman Marcus Group customer online accounts. Affected data included names, contact information, payment card numbers and expiration dates (without CVV), virtual gift card numbers (without PIN), and online account credentials. The incident was discovered in early September 2021. NMG engaged a cybersecurity expert, notified law enforcement, and required password resets for affected accounts.
The Neiman Marcus Group notified customers of a data breach involving unauthorized access to online account information in May 2020. Affected data included names, contact info, payment card numbers (no CVV), virtual gift card numbers, and usernames/passwords/security questions. The company engaged cybersecurity experts and law enforcement, and required password resets for affected accounts. The investigation was ongoing as of the September 30, 2021 notification.
The Neiman Marcus Group, LLC reported an external system breach (hacking) occurring between May 2 and May 17, 2020, discovered on September 9, 2021. The incident affected 4,354,346 individuals in the U.S., including 5,951 Maine residents. Acquired data included names and financial account or credit/debit card numbers with security codes. Substitute notice was sent on September 30, 2021.
Affected (this filing): 4,354,346