Neiman Marcus cyber attacker looks to sell hacked data of ‘high-value rich targets’
What: A recent cyberattack on Neiman Marcus resulted in the alleged hacker, "Sp1d3r," attempting to sell customer data on a cybercrime forum.
Why it is important: The breach exposed sensitive information of potentially millions of high-value customers, raising significant concerns about data security and the implications for those affected.
Neiman Marcus disclosed a significant cyberattack affecting its customer data, with initial reports indicating that 64,000 customers were impacted. However, the hacker, identified as "Sp1d3r," claims the breach affected up to 180 million users. The incident, discovered on May 24, involved unauthorized access to a cloud database managed by Snowflake. Sp1d3r is attempting to sell the stolen data on a cybercrime forum for $150,000 or extort Neiman Marcus into paying for the data's return. The compromised data includes names, contact information, dates of birth, and gift card numbers, though gift card PINs were not exposed.
Neiman Marcus has launched an investigation with cybersecurity experts and notified law enforcement. The retailer took immediate action to contain the breach by disabling access to the affected platform. This incident is part of a broader pattern of recent attacks on Snowflake clients. Snowflake attributed these breaches to compromised credentials obtained through malware rather than vulnerabilities in its platform. This breach underscores the critical need for robust data security measures and the potential risks posed to high-value customers whose information has been exposed.
Neiman Marcus cyber attacker looks to sell hacked data of ‘high-value rich targets!’
