{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:20:56.732Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2018-fin7-breach-of-saks-fifth-avenue-and-lord-taylor-exposes-5-million-payme","title":"FIN7 breach of Saks Fifth Avenue and Lord & Taylor exposes 5 million payment cards","date":"2018-04","date_precision":"month","year":2018,"victim_org":"Hudson's Bay Company (Saks Fifth Avenue, Saks OFF 5TH, Lord & Taylor)","sector":"Retail","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Identity Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":5000000,"threat_actor":"FIN7 / JokerStash (Fin7 syndicate)","summary":"In April 2018 researchers at Gemini Advisory identified a listing on the JokerStash marketplace offering payment card data from Hudson's Bay Company stores. Hudson's Bay confirmed a breach affecting Saks Fifth Avenue, Saks OFF 5TH and Lord & Taylor stores in North America. Roughly five million payment cards were compromised, with in-store point-of-sale systems the source. The intrusion was attributed to the FIN7 syndicate, which gains access through phishing emails opened by employees.","how_it_worked":"FIN7's tradecraft against retail and hospitality victims was consistent: emails written to look like routine business correspondence, carrying a malicious attachment, sent to corporate staff, then reinforced by a phone call from a group member who referenced the message and urged the recipient to open it. Opening the document installed a backdoor and gave the group a corporate foothold from which they reached point-of-sale infrastructure and deployed card-scraping malware. At Hudson's Bay this produced roughly five million card records over about a year, which then surfaced for sale in tranches on an underground marketplace.","lessons":"Network segmentation between corporate email endpoints and payment infrastructure limits how far one opened attachment can travel.","confidence":"Reported","sources":[{"title":"Fin7 Syndicate Hacks Saks Fifth Avenue and Lord & Taylor","url":"https://geminiadvisory.io/fin7-syndicate-hacks-saks-fifth-avenue-and-lord-taylor/","publisher":"Gemini Advisory"},{"title":"Hackers steal payment card data of 5 million Saks, Lord & Taylor customers","url":"https://www.helpnetsecurity.com/2018/04/03/saks-breach/","publisher":"Help Net Security"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2018-fin7-breach-of-saks-fifth-avenue-and-lord-taylor-exposes-5-million-payme"}]}