Saks, Lord & Taylor breach: Data stolen on 5 million cards

Secret Service: How hackers pose as ATM repairmen, steal cash
Secret Service: How hackers pose as ATM repairmen, steal cash

Hackers stole information for more than 5 million credit and debit cards used at Saks Fifth Avenue, Saks Off 5th and Lord & Taylor stores.

Hudson's Bay Company, which owns the retail chains, confirmed the breach Sunday, and said it has "identified the issue, and has taken steps to contain it."

"Once the Company has more clarity around the facts, it will notify customers quickly and will offer those impacted free identity protection services, including credit and web monitoring," Hudson's Bay said in a press release.

The company added that the cards were used for in-store purchases, and there is "no indication" online purchases were affected. Hudson's Bay said it's cooperating with law enforcement in an ongoing investigation.

Related: The Equifax hack could be worse than we thought

A cybersecurity firm called Gemini Advisory identified the breach and posted a blog post detailing its scope. The "attack is amongst the biggest and most damaging to ever hit retail companies," according to the firm.

Gemini Advisory said a hacking syndicate put credit and debit card information it obtained from the hack up for sale on the dark web last week.

A "preliminary analysis" found credit card data was obtained for sales dating back to May 2017, according to the post. The breach likely impacted more than 130 Saks and Lord & Taylor locations across the country, but the "majority of stolen credit cards were obtained from New York and New Jersey locations."

The hackers were also behind notorious data breaches that affected companies including Whole Foods, Chipotle, Omni Hotels & Resorts and Trump Hotels, Gemini Advisory said.

The Saks hack joins a litany of other massive data breaches that continue to plague retailers and tech companies.

Last week, Under Armour revealed the email addresses and usernames for more than 150 million MyFitnessPal accounts was harvested by hackers.

And perhaps the most potentially damaging hack targeted Equifax, a credit reporting agency, last year. The breach affected 145.5 million customers, according to documents reviewed by CNN. Some of the data included names, date of birth, Social Security numbers and home addresses.

CNNMoney Sponsors