Neiman Marcus data breach exposed millions of user email addresses

Neiman Marcus store
(Image credit: Shutterstock / Jonathan Weiss)

It appears the recent breach at Neiman Marcus is a lot bigger than the company claims, with millions of customers possibly affected.

The company confirmed the incident in a breach notification filed with the Office of the Maine Attorney General, but in the same filing said that the breach impacted just under 65,000 people.

However, BleepingComputer discussed the issue with the founder of HaveIBeenPwned?, a service that notifies people when their email addresses are leaked in a data breach. The founder, Troy Hunt, said he analyzed the stolen data, and claims it exposes more than 31 million customer email addresses.

Data for sale

"That's obviously a substantial number and I do want to get notifications out to them promptly. The total unique number of addresses I'll be referring to is 31,152,842," Hunt told BleepingComputer.

Asking Neiman Marcus to comment, BleepingComputer was referred back to the company’s official announcement, meaning it is sticking to its initial assessment of 65,000 affected individuals. 

Sp1d3r took the data from a compromised Snowflake instance, it was said.

"Neiman Marcus Group (NMG) recently learned that an unauthorized party gained access to a cloud database platform used by NMG that is provided by a third party, Snowflake," the company was cited.

Last month, a threat actor with the alias Sp1d3r posted a new archive on the dark web, claiming to hold sensitive data on the customers of the American luxury department store chain, allegedly stolen from a compromised Snowflake instance. 

At the time, they were asking for $150,000, for the database which contained the last four digits of people’s social security numbers, customer transaction data, customer emails, shopping records, employee data, and more.

In a separate announcement on its website, the company said the crooks took people’s names, contact information, birth dates, gift card info, transaction data, partial credit card information, Social Security Numbers, and employee identification numbers.

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
Cartoon Phishing
One of the largest data leaks ever sees info on 1.5 billion people leaked online
A hacker wearing a hoodie sitting at a computer, his face hidden.
North Pole Company data breach exposes details on half a million users
Insurance
Globe Life data breach may have affected 850,000 more patients than previously thought
Suitcase next to a bed in a hotel
Millions of hotel users see personal info checked out in huge data leak
A person with a laptop using a credit card online.
Avery label maker confirms attack on its site, customer credit card info stolen
Latest in Security
Data leak
Top home hardware firm data leak could see millions of customers affected
Representational image depecting cybersecurity protection
Third-party security issues could be the biggest threat facing your business
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Android Logo
Devious new Android malware uses a Microsoft tool to avoid being spotted
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Latest in News
An image of Pro-Ject's Flatten it closed and opened
Pro-Ject’s new vinyl flattener will fix any warped LPs you inadvertently buy on Record Store Day
The iPhone 16 Pro on a grey background
iPhone 17 Pro tipped to get 8K video recording – but I want these 3 video features instead
EA Sports F1 25 promotional image featuring drivers Oscar Piastri, Carlos Sainz and Oliver Bearman.
F1 25 has been officially announced, with this year's entry marking a return for Braking Point and a 'significant overhaul' for My Team mode
Garmin clippd integration
Garmin's golf watches just got a big software integration upgrade to help you improve your game
Robert Downey Jr reveals himself as Doctor Doom to a delighted crowd at San Diego Comic-Con 2024
Marvel is currently revealing the full cast for Avengers: Doomsday, and I think it's going to be a long-winded announcement
Samsung QN90F on yellow background
Samsung announces US prices for its 2025 mini-LED TV lineup, and it’s good and bad news