X
Contacted by us, but you never reached out to the ITRC? Ignore it - it’s a scam!
Skip to content
ITRC logo white final
ITRC-logo-color-final.svg

Support the ITRC

Business Login

Call Now 888.400.5530

  • Victim Help Center
  • Solutions

    Prevent Identity Theft

    Protect your identity from theft and misuse.

    Recover My Identity

    Get direct assistance, a custom remediation plan, and resources if you're a victim.

    Protect My Business

    Explore our business service offerings today.

    Breach Alert

    Get information on the latest data compromises.

    Additional Support

    Vulnerable populations can get additional support to help protect their identity.

  • Resources

    Insights

    Get the latest information on identity crimes.

    Newsletter

    Stay up-to-date on the latest news and happenings from the ITRC.

    Reports

    Explore independent surveys and studies from the ITRC.

    Podcasts

    Hear or read the latest in data security and privacy, as well as identity compromise and crime.

    Events

    Explore upcoming events involving the ITRC.

    Newsroom

    Check out the ITRC’s hub for journalists and policy makers.

  • About the ITRC
  • Contact

Macy’s Sends Data Breach Notification Letter to Customers

Date: 07/11/2018

Home Help Center Macy’s Sends Data Breach Notification Letter to Customers

Department store mainstay Macy’s has sent out data breach notification letters to affected customers of its online shopping site, along with that of its other brand, Bloomingdale’s. The breach, which exposed customers’ usernames, passwords, mailing address email addresses, and payment card information without CVV numbers, has left its investigators scratching their heads in some regards. According to the legally required filing of the breach with the New Hampshire attorney general’s office, IT experts at Macy’s noticed unusual login activity on June 11, 2018. Specifically, there was a spike in logins that day. By following the login pattern, experts were able to track the attacker’s traffic pattern on both macys.com and bloomingdales.com. The strange thing is investigators found there was no compromise of Macy’s web security. The attacker didn’t hack into Macy’s website and start rooting around, but rather used information from an outside source to log into Macy’s customers’ accounts and access encrypted payment card information. In short, someone gained customers’ information—typically from hacking another website or purchasing it online after someone else stole it—and used it to log into other customer accounts on Macys.com and Bloomingdales.com. This serves as a reminder for people who reuse their login credentials from one site to the next. If you’re someone who reuses a username and password combination, this is the exact scenario security experts have warned you about. The potential for credential cracking becomes higher in these cases. Upon discovering the attacker’s activity, Macy’s blocked the accounts that had been accessed and purged their stored payment card information. According to the filing with the AG’s office, most of the cards were Macy’s own department store cards. The company is providing identity monitoring through AllClear ID for customers whose accounts were accessed, and encourages all customers to change their passwords on any websites where they used their same login credentials.


Contact the Identity Theft Resource Center for toll-free, no-cost assistance at (888) 400-5530. For on-the-go assistance, check out the free ID Theft Help App from ITRC.

How much information are you putting out there? It’s probably too much. To help you stop sharing Too Much Information, sign up for the In the Loop.

Get ID Theft News

Stay informed with alerts and newsletters from the Identity Theft Resource Center.

Global 100 2026 awards logo
ITRC 2026 Merit Award Winner
candid seal platinum 2026
Charity Navigator Badge Logo
Facebook-f X-twitter Youtube Linkedin-in Instagram
  • Support Our Mission
  • Our Mission
  • Contact
  • Media Resources
  • Cy Pres Awards
  • FAQ
  • Support Our Mission
  • Our Mission
  • Contact
  • Media Resources
  • Cy Pres Awards
  • FAQ
  • Privacy Policy
  • Live Chat Policy
  • Accessibility
© Copyright 2026 – Identity Theft Resource Center

This website was supported in part by grant number 15POVC-21-GK-01092-NONF and 15POVC-22-GK-01803-NONF, awarded by the Office for Victims of Crime, Office of Justice Programs, U.S. Department of Justice. The opinions, findings, and conclusions or recommendations expressed in this product are those of the contributors and do not necessarily represent the official position or policies of the U.S. Department of Justice. View more about our copyright info here.

  • Victim Help Center
  • Solutions
    • Prevent Identity Theft

      Protect your identity from theft and misuse.

    • Recover My Identity

      Get direct assistance, a custom remediation plan, and resources if you’re a victim.

    • Protect My Business

      Explore our business service offerings today.

    • Breach Alert

      Get information on the latest data compromises.

    • Additional Support

      Vulnerable populations can get additional support to help protect their identity.

  • Resources
    • Insights

      Stay up-to-date on the latest news and happenings from the ITRC.

    • Newsletter

      Stay up-to-date on the latest news and happenings from the ITRC.

    • Reports

      Explore independent surveys and studies from the ITRC.

    • Podcasts

      Hear or read the latest in data security and privacy, as well as identity compromise and crime.

    • Events

      Explore upcoming events involving the ITRC.

    • Newsroom

      Check out the ITRC’s hub for journalists and policy makers.

  • About the ITRC
  • Contact


  • Call Now 888.400.5530