What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Neiman Marcus confirmed that an unauthorized party accessed a database platform it used between April 14 and May 24, 2024. The company began notifying affected people on June 24, 2024. Its Maine regulatory filing lists 64,472 affected people, while independent analysis later reported more than 31 million email addresses in an allegedly stolen dataset. Those figures describe different populations and should not be treated as interchangeable.
What happened in the Neiman Marcus breach?
Neiman Marcus said an unauthorized third party accessed a database platform used by the company. The Maine filing identifies April 14 through May 24, 2024, as the unauthorized-access period and May 24 as the discovery date. Consumer notifications began June 24, 2024. The incident involved data stored in a platform associated with Snowflake.
The company’s notice says it took steps to contain the incident, including disabling access to the affected platform. The public documents do not establish that every record in the platform was accessed or that every listed data category applied to every person.
What information was exposed?
The consumer notification letter said the information varied by individual and could include:
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall#1 Best Overall
- Name or other personal identifiers
- Contact information
- Date of birth
- Neiman Marcus or Bergdorf Goodman gift-card numbers
The letter specifically said gift-card PINs were not included. It did not establish that full payment-card numbers, card security codes, account passwords, or all Social Security numbers were exposed. Later litigation descriptions allege that some records included telephone numbers, expired gift-card information and, for a much smaller group, dates of birth and the last four digits of Social Security numbers. Those descriptions are allegations in court proceedings, not a statement that those fields applied to everyone.
Separately, independent reporting described a broader dataset containing more than 31 million customer email addresses. Neiman Marcus has not publicly authenticated every record or field in that reported dataset.
How many people were affected?
| Figure | What it represents | How to interpret it |
|---|---|---|
| 64,472 people | Neiman Marcus’s official affected-person figure in its Maine filing and notification process | The company’s legally reportable notification population |
| More than 31 million email addresses | Independent analysis of an allegedly stolen dataset, reported in July 2024 | Not an official victim count and not directly comparable with 64,472 |
The gap does not, by itself, prove that either figure is false. A copied dataset can contain duplicate, historical or inactive records; one person can have several email addresses; and state breach-notification rules depend on the type of information and the resident’s jurisdiction. Researchers may also have examined attacker-posted material that the company did not publicly verify.
As of August 18, 2026, the incident has produced consolidated litigation and a reported $3.5 million settlement. The settlement does not establish that every record in the larger alleged dataset belonged to someone entitled to a notice.
Why is Snowflake mentioned?
Snowflake is a cloud data platform that organizations use to store and analyze information. In 2024, Mandiant and Google Cloud described a financially motivated campaign, tracked as UNC5537, in which attackers used previously stolen credentials to enter some customers’ Snowflake environments. Many affected accounts lacked multifactor authentication, and the attackers stole data and attempted extortion.
Mandiant said it had not found evidence that the attackers breached Snowflake’s own corporate environment. Therefore, “Snowflake account hack” is shorthand for compromise of a customer account or instance, not proof of a vulnerability or intrusion in Snowflake’s central systems. Read the technical account at Google Cloud’s Mandiant analysis.
Rank #3
Verified timeline
| Date | Event |
|---|---|
| April 14, 2024 | Start of the unauthorized-access period listed in the Maine filing. |
| May 24, 2024 | Neiman Marcus discovered the incident; the filing also lists this as the end of the access period. |
| June 10, 2024 | Google Cloud and Mandiant published their account of the UNC5537 campaign. |
| June 24, 2024 | Neiman Marcus began consumer notifications. |
| June 25, 2024 | Contemporary reporting described the confirmation as part of the Snowflake-related data-theft campaign. |
| July 2024 | Independent analysis reported more than 31 million email addresses in the allegedly stolen dataset. |
| October 2025 | A federal court order described the incident, notices and litigation. |
| August 18, 2026 | Settlement materials reported a $3.5 million settlement. |
Primary records include the Maine Attorney General filing and the consumer notification letter.
Was payment-card information exposed?
The June 2024 notice identified Neiman Marcus and Bergdorf Goodman gift-card numbers and said gift-card PINs were not exposed. It did not establish that full payment-card numbers or payment-card security codes were part of this incident. A gift-card number is not the same as a credit-card number.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →This event is also separate from Neiman Marcus’s older 2021 payment-card breach, which Maine records describe as affecting approximately 4.35 million U.S. people. Do not combine the 2021 figure with the 2024 incident.
Rank #4
What should customers do now?
1. Treat unexpected messages as phishing
Names, contact details and shopping-related context can make fraudulent messages look credible. Do not click links or open attachments in unsolicited breach-related emails. Open a new browser window and type the official Neiman Marcus or Bergdorf Goodman address yourself.
2. Check gift-card balances carefully
Monitor Neiman Marcus and Bergdorf Goodman gift-card activity. Never send a gift-card number or redemption code to someone who contacts you unexpectedly.
3. Replace reused passwords
The notice did not identify account passwords as exposed, but reusing a password creates risk if that password appears in another breach. Use a unique password for each important account and store it in a reputable password manager.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
4. Turn on multifactor authentication
Enable MFA for email, shopping, financial, social-media and password-manager accounts. MFA is particularly important because stolen credentials were central to the broader Snowflake campaign.
5. Review financial accounts
Check bank and card statements for suspicious activity, even though the public notice did not establish exposure of full payment-card credentials.
6. Freeze your credit when the notice warrants it
If your individual notice identifies a driver’s-license number, Social Security information or other government identification data, consider a free freeze with Experian, Equifax and TransUnion. A freeze helps block new-account fraud; monitoring alone does not.
You can obtain official credit reports through AnnualCreditReport.com. A person whose exposure was limited to contact information and a gift-card number may not need a paid identity-monitoring subscription.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →7. Use only the official settlement site
For eligibility, deadlines and claim instructions, use the settlement administrator at nmgsettlement.com. Eligibility depends on the settlement terms; the existence of a settlement does not prove the full size of the allegedly stolen dataset.
What the public record still does not establish
- That Snowflake’s corporate network was breached.
- That 31 million people were confirmed victims.
- That every notified person had a date of birth or Social Security information exposed.
- That full credit-card numbers, card security codes or gift-card PINs were stolen.
- That attacker branding proves who conducted the Neiman Marcus intrusion.
The Bottom Line
The Neiman Marcus incident is confirmed: an unauthorized party accessed a company-used database platform from April 14 to May 24, 2024, and 64,472 people were included in the company’s official notification process. The separate report of more than 31 million email addresses describes an allegedly broader dataset, not a settled victim count. Protect yourself against phishing, gift-card misuse and credential reuse, and use the official settlement site for current claims information.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




