What happened
In April 2018 researchers at Gemini Advisory identified a listing on the JokerStash marketplace offering payment card data from Hudson's Bay Company stores. Hudson's Bay confirmed a breach affecting Saks Fifth Avenue, Saks OFF 5TH and Lord & Taylor stores in North America. Roughly five million payment cards were compromised, with in-store point-of-sale systems the source. The intrusion was attributed to the FIN7 syndicate, which gains access through phishing emails opened by employees.
How the deception worked
FIN7's tradecraft against retail and hospitality victims was consistent: emails written to look like routine business correspondence, carrying a malicious attachment, sent to corporate staff, then reinforced by a phone call from a group member who referenced the message and urged the recipient to open it. Opening the document installed a backdoor and gave the group a corporate foothold from which they reached point-of-sale infrastructure and deployed card-scraping malware. At Hudson's Bay this produced roughly five million card records over about a year, which then surfaced for sale in tranches on an underground marketplace.
The control that would have caught it· our reading, not a claim from the sources
Network segmentation between corporate email endpoints and payment infrastructure limits how far one opened attachment can travel.
Sources (2)
- Fin7 Syndicate Hacks Saks Fifth Avenue and Lord & TaylorGemini Advisory·geminiadvisory.ioOpen ↗
- Hackers steal payment card data of 5 million Saks, Lord & Taylor customersHelp Net Security·helpnetsecurity.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.