{
  "id": "case-neiman-marcus-pos",
  "slug": "neiman-marcus-pos-malware-breach",
  "title": "Neiman Marcus 1.1 Million Payment Card In-Memory Scraping",
  "summary": "Sophisticated memory-scraping malware intrusion into point-of-sale systems across 77 Neiman Marcus luxury department stores, capturing payment card Track 2 data in memory over a four-month stealth campaign, resolved through a multi-state Attorney General consent decree.",
  "case_number": "2019-CH-00438",
  "court": "Circuit Court of Cook County, Illinois",
  "district": "N.D. Ill.",
  "country": "United States",
  "opened_at": "2014-01-10",
  "status": "settled",
  "victim_sector": "Retail & Luxury Goods",
  "victim_country": "United States",
  "loss_amount_usd": 25000000,
  "loss_amount_note": "Multi-state AG settlement, card reissuance fees, and forensic reviews.",
  "first_seen_at": "2013-07-16T00:00:00Z",
  "last_updated_at": "2026-10-06T10:00:00Z",
  "actor_slug": "unattributed-cybercrime",
  "defendant_slugs": [],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1003",
      "evidence_excerpt": "Custom RAM scraper malware monitored process memory of payment gateway applications, copying unencrypted magnetic stripe Track 2 data before encryption.",
      "evidence_locator": "Multi-State AG Settlement Agreement \u00b6 8",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Multi-State AG Settlement Order",
      "source_url": "https://ag.ny.gov",
      "technique_name": "OS Credential Dumping",
      "tactic": "Credential Access"
    },
    {
      "technique_id": "T1056.001",
      "evidence_excerpt": "Malware remained resident on store registers across 77 locations, executing automated scraping routines between July and October 2013.",
      "evidence_locator": "Forensic Investigation Report Summary",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Neiman Marcus Customer Notice",
      "source_url": "https://www.neimanmarcus.com",
      "technique_name": "Keylogging",
      "tactic": "Credential Access"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2013-07-16",
      "description": "Malware is deployed across store register terminals in 77 Neiman Marcus retail properties."
    },
    {
      "event_type": "discovery",
      "event_date": "2013-12-15",
      "description": "Card brands alert Neiman Marcus to fraudulent card transactions originating from store registers."
    },
    {
      "event_type": "settlement",
      "event_date": "2019-01-08",
      "description": "Neiman Marcus reaches $1.5 million settlement with 43 state Attorneys General."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Unrestricted network traversal from corporate intranet into point-of-sale register environments across 77 Neiman Marcus luxury department stores.",
    "blast_radius": "1.1 million customer payment cards compromised via memory-scraping malware over four months, resulting in a 43-state Attorney General settlement and $25M+ in costs.",
    "kill_chain": [
      {
        "phase": "Initial Foothold",
        "title": "Corporate Intranet Infiltration",
        "description": "Threat actors entered the corporate network through compromised credentials, establishing persistent footholds on management servers.",
        "technical_artifacts": [
          "Stolen domain credentials",
          "Internal pivot tools"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Store Register Pivoting",
        "title": "Point-of-Sale Subnet Traversal",
        "description": "Adversaries traversed unsegmented network boundaries connecting corporate headquarters to register terminals in 77 retail stores.",
        "technical_artifacts": [
          "Internal SMB propagation",
          "Register management shares"
        ],
        "mitre_technique_id": "T1021.002"
      },
      {
        "phase": "Memory Scraping",
        "title": "RAM Scraper Malware Deployment",
        "description": "Custom malware was installed on checkout registers, intercepting unencrypted payment card Track 2 data resident in system memory.",
        "technical_artifacts": [
          "RAM scraper payload",
          "Memory read hooks"
        ],
        "mitre_technique_id": "T1003"
      },
      {
        "phase": "Batch Exfiltration",
        "title": "Encrypted Card Batch Exfiltration",
        "description": "Scraped card numbers were aggregated into encrypted staging files and exfiltrated to adversary-controlled servers over external ports.",
        "technical_artifacts": [
          "Encrypted card batch archives",
          "Outbound FTP/HTTP streams"
        ],
        "mitre_technique_id": "T1041"
      },
      {
        "phase": "Regulatory Settlement",
        "title": "43-State Attorney General Settlement",
        "description": "Following detection by payment card brands, Neiman Marcus settled consumer protection claims with 43 state Attorneys General.",
        "technical_artifacts": [
          "Multi-state AG consent judgment",
          "Mandated security audits"
        ],
        "mitre_technique_id": "T1078"
      }
    ],
    "defensive_takeaways": [
      "Implement Point-to-Point Encryption (P2PE) so payment card data is never decrypted in workstation memory.",
      "Strictly segment the Cardholder Data Environment (CDE) from general corporate workstations and subnets.",
      "Deploy application whitelisting on store point-of-sale registers to prevent execution of unapproved binaries.",
      "Continuously monitor register endpoint processes for unauthorized memory inspection and raw disk access."
    ]
  }
}