
Luxury retailer Neiman Marcus confirmed a data breach after hackers attempted to sell the company’s stolen database after recent Snowflake data theft attacks. According to a data breach notification filed with the Office of the Maine Attorney General, the breach impacted 64,472 individuals.
Neiman Marcus stated that an unauthorized third party accessed a database platform used by the company between April and May 2024. The compromised information varied by individual and included names, contact details, birth dates, and Neiman Marcus or Bergdorf Goodman gift card numbers, although gift card PINs were not included.
Upon discovering the breach, Neiman Marcus disabled access to the affected database launched an investigation with cybersecurity experts, and notified law enforcement. The company confirmed that the data was stolen from its Snowflake account.
The breach was linked to a threat actor, "Sp1d3r," who listed Neiman Marcus’ data for sale on a hacking forum for $150,000. This actor is reportedly involved in multiple breaches related to the Snowflake data thefts. While the threat actor did not explicitly mention Snowflake, they referred to "Raped Flake," a custom tool used to steal data from the database platform.
The stolen data also included the last four digits of social security numbers, customer transactions, emails, shopping records, employee data, and millions of gift card numbers. The threat actor claimed to have attempted extortion before the forum listing, which was taken down shortly after posting, possibly indicating negotiations with Neiman Marcus.
A joint investigation by Snowflake, Mandiant, and CrowdStrike revealed that the threat actor tracked as UNC5537, used stolen customer credentials to target at least 165 organizations lacking multi-factor authentication protection. Mandiant linked these attacks to a financially motivated group known for breaching organizations, stealing data, and attempting extortion.
The threat actor exploited credentials stolen by information-stealing malware dating back to 2020. Many impacted accounts had not enabled multi-factor authentication and used outdated credentials. Snowflake and Mandiant have notified approximately 165 potentially exposed organizations, which include Santander, Ticketmaster, QuoteWizard/LendingTree, Advance Auto Parts, Los Angeles Unified School District, and Pure Storage.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543