CASE DOSSIER settled

Neiman Marcus 1.1 Million Payment Card In-Memory Scraping

Docket: 2019-CH-00438 Court: Circuit Court of Cook County, Illinois Opened: 2014-01-10 Sector: Retail & Luxury Goods

Key Facts

Status
SETTLED
Legal disposition
Loss Amount
$25.0 million
Multi-state AG settlement, card reissuance fees, and forensic reviews.
Techniques
2
Verified mappings
Defendants
0
Named in charges
  • Legal Status: SETTLED in Circuit Court of Cook County, Illinois.
  • Primary Target Sector: Retail & Luxury Goods.
  • Documented Financial Loss: $25.0 million.
  • 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Sophisticated memory-scraping malware intrusion into point-of-sale systems across 77 Neiman Marcus luxury department stores, capturing payment card Track 2 data in memory over a four-month stealth campaign, resolved through a multi-state Attorney General consent decree.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Unrestricted network traversal from corporate intranet into point-of-sale register environments across 77 Neiman Marcus luxury department stores.

Operational & Financial Fallout

1.1 million customer payment cards compromised via memory-scraping malware over four months, resulting in a 43-state Attorney General settlement and $25M+ in costs.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: SETTLED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Unrestricted network traversal from corporate intranet into point-of-sale register environments across 77 Neiman Marcus luxury department stores.

Adversary Kill Chain Flow

5 Documented Phases
1
Initial Foothold Corporate Intranet Infiltration
MITRE ATT&CK T1078 →

Threat actors entered the corporate network through compromised credentials, establishing persistent footholds on management servers.

Artifacts & Tooling: Stolen domain credentials Internal pivot tools
2
Store Register Pivoting Point-of-Sale Subnet Traversal
MITRE ATT&CK T1021.002 →

Adversaries traversed unsegmented network boundaries connecting corporate headquarters to register terminals in 77 retail stores.

Artifacts & Tooling: Internal SMB propagation Register management shares
3
Memory Scraping RAM Scraper Malware Deployment
MITRE ATT&CK T1003 →

Custom malware was installed on checkout registers, intercepting unencrypted payment card Track 2 data resident in system memory.

Artifacts & Tooling: RAM scraper payload Memory read hooks
4
Batch Exfiltration Encrypted Card Batch Exfiltration
MITRE ATT&CK T1041 →

Scraped card numbers were aggregated into encrypted staging files and exfiltrated to adversary-controlled servers over external ports.

Artifacts & Tooling: Encrypted card batch archives Outbound FTP/HTTP streams
5
Regulatory Settlement 43-State Attorney General Settlement
MITRE ATT&CK T1078 →

Following detection by payment card brands, Neiman Marcus settled consumer protection claims with 43 state Attorneys General.

Artifacts & Tooling: Multi-state AG consent judgment Mandated security audits
Real-World Blast Radius & Operational Fallout

1.1 million customer payment cards compromised via memory-scraping malware over four months, resulting in a 43-state Attorney General settlement and $25M+ in costs.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Implement Point-to-Point Encryption (P2PE) so payment card data is never decrypted in workstation memory.
✓ Strictly segment the Cardholder Data Environment (CDE) from general corporate workstations and subnets.
✓ Deploy application whitelisting on store point-of-sale registers to prevent execution of unapproved binaries.
✓ Continuously monitor register endpoint processes for unauthorized memory inspection and raw disk access.

Procedural & Incident Timeline

2013-07-16 incident

Malware is deployed across store register terminals in 77 Neiman Marcus retail properties.

2013-12-15 discovery

Card brands alert Neiman Marcus to fraudulent card transactions originating from store registers.

2019-01-08 settlement

Neiman Marcus reaches $1.5 million settlement with 43 state Attorneys General.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1003 OS Credential Dumping
Credential Access
"Custom RAM scraper malware monitored process memory of payment gateway applications, copying unencrypted magnetic stripe Track 2 data before encryption." Multi-State AG Settlement Agreement ¶ 8 reviewed
T1056.001 Keylogging
Credential Access
"Malware remained resident on store registers across 77 locations, executing automated scraping routines between July and October 2013." Forensic Investigation Report Summary reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, Neiman Marcus 1.1 Million Payment Card In-Memory Scraping, No. 2019-CH-00438 (Circuit Court of Cook County, Illinois 2014), https://cybercaselibrary.com/cases/neiman-marcus-pos-malware-breach/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/neiman-marcus-pos-malware-breach" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>