Ending Soon! Save 33% on All Access

Neiman's Hack Attack Is Looking More and More Like Target's Neiman Marcus reported that a more-than-expected 1.1 million shoppers may have been affected by a hack job that employed similar malware to the kind that compromised Target.

By Geoff Weiss

Opinions expressed by Entrepreneur contributors are their own.

Joe Mabel

New details have come to light about the Neiman Marcus security breach, revealing that over 1.1 million consumers may have been victimized by a scheme that appears strikingly similar to the attack that besieged as many as 100 million Target shoppers last month.

Investigators have not revealed if the same cybercriminals are suspected in the Neiman Marcus breach as the loose band of Eastern European hackers suspected in Target's theft, reports The New York Times. However, "security specialists working with the authorities have said that the hackers were considering several major retailers as potential targets."

In both cases, RAM-scraping malware appears to have been installed on point-of-sale terminals using a Trojan tool in an operation that investigators are calling Kaptoxa, reports Wired. "The code is based on a previous malicious tool known as BlackPOS that is believed to have been developed in 2013 in Russia."

In an apology on Neiman Marcus's website, president and CEO Karen Katz disclosed that hackers attempted to "scrape" credit card data last year between July 16 and Oct. 30. To date, approximately 2,400 cards had been used fraudulently, she said.

Related: 37 South Korean Bank Execs Offer to Resign Over Breach. Should Target Execs Follow Suit?

However, Katz assured that no Social Security numbers or birth dates were comprised; no Neiman Marcus or Bergdorf Goodman cards had been used fraudulently; online shoppers were not affected; and PINs were not at risk. Like Target, Neiman Marcus will offer one year of free credit monitoring and identity-theft protection to anybody who shopped with the store in the last year.

According to the Times, this rash of breaches has reignited discussion that the U.S. should adopt the same EMV credit card technology that is pervasive throughout the rest of the world, in which cards have a small chip that generates a new code for every transaction.

The only hitch is, "retailers and card issuers have worried that the cost of adopting the technology, usually estimated at $15 billion to $30 billion, would be more than the cost of the fraud it prevented."

Related: Target, Neiman Marcus Credit Card Hacks Could Be More Widespread, Experts Say

Geoff Weiss

Former Staff Writer

Geoff Weiss is a former staff writer at Entrepreneur.com.

Want to be an Entrepreneur Leadership Network contributor? Apply now to join.

Business Ideas

63 Small Business Ideas to Start in 2024

We put together a list of the best, most profitable small business ideas for entrepreneurs to pursue in 2024.

Business Models

How to Become an AI-Centric Business (and Why It's Crucial for Long-Term Success)

Learn the essential steps to integrate AI at the core of your operations and stay competitive in an ever-evolving landscape.

Business News

'Creators Left So Much Money on the Table': Kickstarter's CEO Reveals the Story Behind the Company's Biggest Changes in 15 Years

In an interview with Entrepreneur, Kickstarter CEO Everette Taylor explains the decision-making behind the changes, how he approaches leading Kickstarter, and his advice for future CEOs.