Neiman Marcus notified customers in mid-2024 that an unauthorised party had obtained information stored on a database platform provided by a third party. The incident is among those subsequently linked to the campaign against Snowflake customer environments filed at 24-0602.
A Named Victim Of An Unnamed Platform
The retailer’s notification described a third-party database platform without naming it. Customers therefore learned that their data had gone, and could not learn from whom.
That is standard practice and it makes the campaign hard to see from any single notification. Only when several disclosures were read together did the common platform become obvious, which is a reason a corpus is worth keeping at all.
The Count That Was Never Published
No affected-customer figure appeared in the retailer’s own disclosure, and we are not carrying one from elsewhere.
Graded medium: the link to the wider campaign is well reported, the scope is not, and the platform is named nowhere in the company’s account.
Compiled from public reporting of the company’s notifications, listed below. No affected-customer count was published and we are not asserting one. Corrections: corrections@forensicpost.com.