Yes, the Neiman Marcus data breach compromised shopper information. The luxury retailer’s systems were breached on April 14, 2024, and discovered on May 24, 2024, exposing sensitive customer data including names, email addresses, dates of birth, gift card information, partial credit card numbers, and the last four digits of Social Security numbers. While Neiman Marcus’s official notification stated that 64,472 people were directly impacted, security researchers later identified that more than 31 million customer email addresses were exposed in the incident. The breach was part of a larger wave of attacks targeting Snowflake data platform users, making it one of the significant retail security incidents of 2024.
A class action settlement has already been approved and processed. In the case Sherman v. The Neiman Marcus Group LLC, filed in U.S. District Court for the District of Montana, a $3.5 million settlement received final approval on October 23, 2025. However, if you were a Neiman Marcus customer, the claim filing deadline of October 8, 2025 has already passed, meaning new claims are no longer being accepted as of June 2026.
Table of Contents
- What Information Was Stolen in the Neiman Marcus Breach?
- How Did the Breach Happen and Why Was Neiman Marcus Vulnerable?
- Settlement Amount and What the Class Action Provides
- How Were Customers Supposed to Claim Compensation?
- Mandatory Security Improvements Required by the Settlement
- Timeline of the Neiman Marcus Breach and Discovery
- Defendant’s Position and Denial of Wrongdoing
What Information Was Stolen in the Neiman Marcus Breach?
The Neiman Marcus breach exposed multiple categories of sensitive personal information, making it a high-risk incident for affected customers. Compromised data included full names, email addresses, dates of birth, gift card account information, partial credit card numbers, and the last four digits of Social Security numbers. This combination of information is particularly dangerous because fraudsters can use the personal identifiers (name, DOB, SSN partial) to attempt identity theft, while the partial credit card data could be cross-referenced with other breached databases to reconstruct full card numbers. The discrepancy between the 64,472 customers that Neiman Marcus officially notified and the 31 million exposed email addresses highlights a critical challenge in breach response.
The official figure likely represents customers whose records contained the full range of sensitive data, while the broader email exposure suggests that Neiman Marcus’s snowflake database contained legacy customer information dating back years. This means you could have been exposed even if you hadn’t shopped at Neiman Marcus recently—dormant accounts and historical customer files were compromised alongside active accounts. A real-world concern: if you received a Neiman Marcus data breach notification but didn’t see your email address listed publicly, you may still have been exposed in the larger 31 million email dump. Security researchers discovered the breach by finding databases for sale on dark web forums before the full scope was publicly acknowledged.
- —
How Did the Breach Happen and Why Was Neiman Marcus Vulnerable?
The Neiman Marcus breach was not the result of a direct attack on the retailer’s infrastructure. Instead, attackers compromised Neiman Marcus’s Snowflake account—the cloud data platform that stores and manages customer databases. Snowflake is a widely used tool across the retail, finance, and healthcare industries, making it an attractive target. The breach was part of a coordinated series of attacks in mid-2024 that exploited weak or reused credentials to access multiple organizations’ Snowflake instances without triggering traditional network security defenses. Neiman Marcus’s use of Snowflake meant that customer data was stored off-premises in a cloud environment.
While cloud storage offers benefits like redundancy and scalability, it also creates a different attack surface. The attackers gained access to Neiman Marcus’s Snowflake account and were able to download vast amounts of customer data without triggering alerts on Neiman Marcus’s retail networks. The discovery lag—38 days between the initial breach and Neiman Marcus’s discovery—suggests that the retailer did not have continuous monitoring of its Snowflake account activity, which is a significant operational limitation that the settlement’s mandatory security improvements aim to address. An important limitation: Neiman Marcus was not unique in this vulnerability. Dozens of organizations using Snowflake with weak password hygiene or single-factor authentication were compromised in the same wave. This was an industry-wide problem, not a failure specific to Neiman Marcus alone, though the retailer’s delayed discovery and the subsequent scale of the exposure reflect specific gaps in their security monitoring practices.
- —
Settlement Amount and What the Class Action Provides
The class action settlement totaled $3.5 million, with eligible claimants able to receive up to $2,500 for documented out-of-pocket losses directly caused by the breach. Documented losses include bank fees incurred due to fraudulent charges, costs paid for credit monitoring or credit repair services, communication charges related to identity theft recovery, and expenses for credit card replacements. This is a “documented loss” standard, meaning you needed to keep receipts and provide proof of the expense to claim compensation. Alternatively, claimants could forgo the up-to-$2,500 cash compensation and instead enroll in two years of free credit monitoring services provided by a third-party vendor. This option was beneficial for customers who did not experience direct financial losses but wanted ongoing protection against identity theft risk.
The credit monitoring typically includes continuous scanning of credit reports, dark web monitoring for exposed credentials, and alerts if a new credit account is opened in your name. A critical tradeoff: The claim filing deadline was October 8, 2025, and that deadline has now passed. As of June 2026, the settlement is closed to new claims. If you did not file a claim by that date, you have lost the opportunity to receive compensation from this settlement, even if you were directly harmed by the breach. Class action settlements have strict deadlines, and extensions are rarely granted once the final claim period has closed.
- —
How Were Customers Supposed to Claim Compensation?
Customers who were affected by the Neiman Marcus breach and wanted to claim compensation were required to submit a claim form to the settlement administrator before the October 8, 2025 deadline. The claim process typically involved visiting the official settlement website (nmgsettlement.com), completing an online form or submitting a paper form by mail, and providing documentation of either the breach notification received from Neiman Marcus or proof of being a customer during the relevant time period. For those claiming documented losses, receipts and proof of payment were required. The settlement administrator reviewed each claim to verify eligibility and determine the appropriate compensation level. The review process could take several weeks or months after the claim period ended, with payments distributed in batches once claims were approved.
Claimants who received notification letters from Neiman Marcus were prioritized, as the notification itself served as proof of exposure. Customers who did not receive a breach notification but believed they were Neiman Marcus customers during the exposure period could still file, though they needed to provide additional documentation of their customer status. A comparison worth noting: different data breach class action settlements have different claim approval rates. Some settlements see as few as 2–3% of eligible class members actually file claims, while others see higher rates if the settlement amount is substantial and the claim process is simple. The Neiman Marcus settlement’s up-to-$2,500 cash option and straightforward online filing process encouraged higher claim rates than settlements requiring only credit monitoring enrollment, but the window to participate has now permanently closed.
- —
Mandatory Security Improvements Required by the Settlement
As part of the settlement agreement, the Neiman Marcus Group accepted a series of mandatory security enhancements designed to prevent similar breaches in the future. These improvements include the appointment of a Chief Information Security Officer (CISO) responsible for overseeing all security functions, creation of a dedicated Information Security organizational unit with defined roles and responsibilities, and increased frequency of cybersecurity reporting to senior management and the board of directors. The settlement also requires implementation of chip-based payment card infrastructure in physical stores to reduce the risk of credit card data theft at point-of-sale terminals. Additional requirements include mandatory enhanced employee education and training on privacy and data security, with documented participation from all staff. The settlement specifies that these improvements must be implemented and maintained for a defined period, with regular audit and compliance verification.
An independent security assessor was appointed to verify that Neiman Marcus met these commitments, with audit reports filed with the court. A critical limitation: while these improvements address some operational security gaps, they do not guarantee that breaches cannot occur in the future. Neiman Marcus’s reliance on Snowflake for customer data storage means the retailer remains dependent on the security controls and credential management of a third-party vendor. Chip-based payment infrastructure in stores does not protect cloud-stored customer data. The settlement’s security improvements are designed to reduce risk and improve incident detection speed, but they represent baseline industry standards rather than comprehensive protection.
- —
Timeline of the Neiman Marcus Breach and Discovery
The Neiman Marcus breach occurred on April 14, 2024, but the retailer did not discover the intrusion until May 24, 2024—a 40-day window during which attackers had unrestricted access to customer data. This discovery lag is significant because it extended the period of potential data exfiltration and prevented immediate incident response. Neiman Marcus began its breach notification process on May 24, 2024, and sent customer notification letters in the following weeks. The official notification stated that 64,472 customers were directly affected, though this figure was later revised as researchers identified the broader exposure affecting millions of email addresses.
The class action lawsuit was filed shortly after breach notifications began, with the case docketed in U.S. District Court for the District of Montana. Settlement negotiations took place over several months, with the defendant (The Neiman Marcus Group LLC) denying any wrongdoing but agreeing to settle to avoid the cost and risk of protracted litigation. Final settlement approval was granted on October 23, 2025, followed by the claim filing period ending on October 8, 2025 (a staggered timeline typical of class action administration).
- —
Defendant’s Position and Denial of Wrongdoing
The Neiman Marcus Group LLC’s formal response to the lawsuit included a denial of any wrongdoing, a standard legal posture in settlement agreements. The defendant argued that the breach resulted from criminal acts by third parties targeting the Snowflake platform and that Neiman Marcus had implemented reasonable security measures appropriate to the industry. However, the company agreed to settle the case to avoid the uncertainties and expenses of lengthy litigation, including potential discovery of internal security assessments, expert testimony on security standards, and jury trial risks.
This settlement framework—where the defendant neither admits nor denies wrongdoing but agrees to pay compensation—is the standard outcome in data breach class actions. From a practical standpoint, the settlement’s $3.5 million payout and mandatory security improvements acknowledge that customers were harmed and that changes were needed, regardless of formal legal liability determinations. For customers who experienced identity theft, credit card fraud, or incurred expenses monitoring their credit after the breach, the settlement provided a mechanism for compensation without requiring proof that Neiman Marcus was negligent or violated specific laws.
Sources
- Neiman Marcus Data Breach Settlement — Claims Closed — the settlement record: what the case covered, what it paid and how it closed, from our sister site OpenClassActions.com.
You Might Also Like
- Labcorp Data Breach Class Action Claims Patient Billing Information Was Compromised
- Quest Diagnostics Data Breach Class Action Claims Lab Patient Information Was Exposed
- Ascension Data Breach Class Action Claims Hospital Patient Information Was Exposed