The Neiman Marcus data breach affected a significant number of users, exposing personal information that can be used for identity theft, phishing, and fraud. If you've ever had an account or relationship with Neiman Marcus, it's worth checking whether your data was involved.
What Happened
Neiman Marcus experienced two significant breaches. The first, disclosed in January 2014, involved point-of-sale malware active on store systems from July to October 2013, compromising around 1.1 million payment cards. The second, disclosed in 2021, involved unauthorized access to an online cloud database between 2015 and 2019 that went undetected until 2020, affecting approximately 4.6 million customers.
What Data Was Exposed
The 2013 incident exposed payment card numbers and expiration dates. The 2021-disclosed cloud breach exposed names, contact information, and for a subset of about 85,000 customers, payment and gift card numbers along with security codes; some Social Security numbers were also affected for a smaller group.
Why This Still Matters
Even breaches from years ago remain a risk today. Stolen data is sold, traded, and reused indefinitely. Credentials from old breaches fuel credential stuffing attacks — automated attempts to reuse your email and password combination on other sites. If you reused a password anywhere, one old breach can compromise several current accounts.
How to Check If You Were Affected
Use our free breach checker below — enter your email and we'll scan it against known breach databases instantly, no signup required.
What to Do If You Were Affected
- Change any reused password immediately, starting with your most sensitive accounts.
- Enable two-factor authentication wherever it's offered.
- Monitor financial accounts closely if payment or banking data was involved.
- Watch for phishing — breach data is often used to craft convincing scam messages.
- Freeze your credit if your SSN or government ID number was exposed.
👉 Check your own exposure in 30 seconds → scan your email free.
Frequently Asked Questions
When did the Neiman Marcus data breaches happen?
Neiman Marcus experienced two major incidents: point-of-sale malware active from July to October 2013 (disclosed January 2014), and unauthorized access to a cloud database that occurred between 2015 and 2019 but wasn't discovered until 2020 (disclosed 2021).
What data was stolen in the Neiman Marcus breaches?
The 2013 incident exposed roughly 1.1 million payment card numbers and expiration dates. The later cloud breach exposed names and contact details for 4.6 million customers, with payment/gift card numbers and security codes exposed for about 85,000, and Social Security numbers for a smaller subset.
How do I check if I was affected by a Neiman Marcus breach?
Neiman Marcus notified affected customers directly for both incidents. You can also check your email at Scan My Shadow and monitor your bank and credit card statements for unauthorized charges.
Was Neiman Marcus fined for these breaches?
Neiman Marcus reached a $1.5 million multistate settlement related to the 2013 breach for security failures, and faced additional legal scrutiny after the 2021-disclosed cloud breach.
What should I do if my Neiman Marcus gift card data was exposed?
Check your gift card balances for unauthorized use, contact Neiman Marcus customer service to report suspicious activity, and monitor any linked payment methods for fraud.