Closed
Neiman Marcus Data Breach Settlement
The claim window closed on October 1, 2020. After seven years of litigation, the revised settlement was finally approved on June 4, 2021, and payments were administered afterward.
Case record
- Case
- Remijas, et al. v. The Neiman Marcus Group, LLC
- Case no.
- 1:14-cv-01735
- Court
- U.S. District Court for the Northern District of Illinois, Eastern Division
- Defendant
- The Neiman Marcus Group, LLC
- Administrator
- Angeion Group
- Settlement fund
- $1.6 million ($1.2 million payments fund plus up to $400,000 for administration)
The case
What this settlement was about
In January 2014, Neiman Marcus disclosed that hackers had planted malware in its payment systems capable of scraping credit and debit card data at its stores. Approximately 370,000 payment cards were potentially exposed during the malware period, July 16 to October 30, 2013, and at least 9,200 of those cards were later used fraudulently.
The litigation produced a landmark ruling: the Seventh Circuit's 2015 Remijas decision was one of the first appellate opinions to hold that data breach victims have standing to sue based on the increased risk of future fraud. The case then took over seven years to resolve, a first settlement proposed in 2017 was never finally approved after objections, and a revised settlement with a narrower class won final approval only on June 4, 2021.
Along the way, Neiman Marcus filed for Chapter 11 bankruptcy in May 2020; class counsel negotiated a bankruptcy court stipulation ensuring the settlement would not be reduced. Neiman Marcus also documented security changes, including hiring a chief information security officer and deploying chip-based payment terminals in all stores, and separately paid $1.5 million to resolve a 43-state attorneys general investigation into the same breach.
The class
Who was covered
All U.S. residents who held a credit or debit card account used in any Neiman Marcus Group store at any time from July 16, 2013 through October 30, 2013, the period the payment card malware was active.
- What class members could receiveUp to $100 for class members whose card was used at a store while the malware was operating there, and up to $25 for other class members with valid claims, both subject to pro rata reduction.
- Proof requirementClaims required supporting documentation.
- Claim deadlinePassed on Oct 1, 2020. New claims are no longer accepted.
Docket timeline
How the settlement unfolded
- Jul 16 – Oct 30, 2013Malware active in stores
Payment card scraping malware exposed about 370,000 cards; at least 9,200 were later used fraudulently.
- January 2014Class action filed
Customers sued within weeks of Neiman Marcus disclosing the breach.
- July 2015Seventh Circuit ruling
Remijas v. Neiman Marcus became a landmark decision on data breach standing.
- October 1, 2020Claim deadline (revised settlement)
Claims filed under the earlier, never-approved 2017 settlement were honored.
- June 4, 2021Final approval
The revised settlement was approved after the June 2 fairness hearing, over seven years after filing.
- 2021Distribution
Payments were administered after final approval.
Questions people still ask
Frequently asked questions
Can I still file a Neiman Marcus data breach claim?
No. The claim deadline for the revised settlement was October 1, 2020, and final approval came on June 4, 2021. The claims process is closed.
How much did the Neiman Marcus settlement pay?
Class members whose card was used at a store on a date and time the malware was operating there could receive up to $100; other valid claimants could receive up to $25, both subject to pro rata reduction.
Why did this case take seven years?
A first $1.6 million settlement proposed in 2017 was never finally approved after objections. A revised settlement with a narrower class was negotiated, then Neiman Marcus's May 2020 bankruptcy added another hurdle before final approval in June 2021.
Why is this case legally significant?
The Seventh Circuit's 2015 Remijas decision was one of the first appellate rulings to hold that data breach victims have standing to sue based on the increased risk of future fraud, a precedent still cited in data breach litigation today.
Did Neiman Marcus face other penalties for the breach?
Yes. Separately from this class action, Neiman Marcus paid $1.5 million in January 2019 to resolve a 43-state attorneys general investigation into the same breach.
Sources for this record
Official site nmsettlement.com has been retired. Record preserved by TapClaim.