Neiman Marcus 1.1 Million Payment Card In-Memory Scraping
Key Facts
- Legal Status: SETTLED in Circuit Court of Cook County, Illinois.
- Primary Target Sector: Retail & Luxury Goods.
- Documented Financial Loss: $25.0 million.
- 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Unrestricted network traversal from corporate intranet into point-of-sale register environments across 77 Neiman Marcus luxury department stores.
Operational & Financial Fallout
1.1 million customer payment cards compromised via memory-scraping malware over four months, resulting in a 43-state Attorney General settlement and $25M+ in costs.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Unrestricted network traversal from corporate intranet into point-of-sale register environments across 77 Neiman Marcus luxury department stores.
Adversary Kill Chain Flow
5 Documented PhasesThreat actors entered the corporate network through compromised credentials, establishing persistent footholds on management servers.
Adversaries traversed unsegmented network boundaries connecting corporate headquarters to register terminals in 77 retail stores.
Custom malware was installed on checkout registers, intercepting unencrypted payment card Track 2 data resident in system memory.
Scraped card numbers were aggregated into encrypted staging files and exfiltrated to adversary-controlled servers over external ports.
Following detection by payment card brands, Neiman Marcus settled consumer protection claims with 43 state Attorneys General.
1.1 million customer payment cards compromised via memory-scraping malware over four months, resulting in a 43-state Attorney General settlement and $25M+ in costs.
Procedural & Incident Timeline
Malware is deployed across store register terminals in 77 Neiman Marcus retail properties.
Card brands alert Neiman Marcus to fraudulent card transactions originating from store registers.
Neiman Marcus reaches $1.5 million settlement with 43 state Attorneys General.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1003 | OS Credential Dumping Credential Access | "Custom RAM scraper malware monitored process memory of payment gateway applications, copying unencrypted magnetic stripe Track 2 data before encryption." | Multi-State AG Settlement Agreement ¶ 8 | reviewed |
| T1056.001 | Keylogging Credential Access | "Malware remained resident on store registers across 77 locations, executing automated scraping routines between July and October 2013." | Forensic Investigation Report Summary | reviewed |