In January 2016, The Neiman Marcus Group detected unauthorized access to its mobile app environment via automated brute-force attacks using credentials stolen from other breaches. Attackers accessed customer names, addresses, phone numbers, last four digits of credit cards, expiration dates, and gift card account numbers. Full credit card numbers were not accessed. The company updated app security controls and required password resets for affected accounts.