
Macy’s
Data Breach on November 24, 2025
| Data Breach Report | |||
|---|---|---|---|
| Victim | macys.com | ||
| Threat Actor | CL0P | ||
| Date Discovered | Nov 24, 2025 | ||
| Description | Macy’s, Inc. is a major U.S. department store company based in the USA, operating a national network of Macy’s stores, offering a wide assortment of apparel, home goods, jewelry, beauty, and more through both its physical stores and e-commerce platform. | ||
| Leak Size | Unknown |
Credential Exposure for macys.com
We've indexed 21,720 @macys.com accounts from external breaches, plus 23,434 credentials for macys.com itself.
Last checked Aug 16, 2026
| @macys.com addresses from external breaches | |
|---|---|
| Combo lists | 14,076 accounts · most recent Aug 15, 2026 |
| Third-party breaches | 10,376 accounts · across 520 breaches · 9,690 with a plaintext password · most recent Jun 9, 2026 |
| Phishing pages | 32 accounts · most recent Aug 13, 2026 |
| Passwords for macys.com accounts | |
|---|---|
| Combo lists | 14,110 logins · most recent Aug 15, 2026 |
| Infostealer logs | 9,856 logins · 6,935 infected devices · most recent Aug 8, 2026 |
Logins may belong to customers or to staff, and the data doesn't say which. None of this is necessarily connected to the ransomware attack above.
Is your organization next?
Macy’s was breached. Check if your company's credentials have been exposed in this or other data breaches.
Check your exposure →Continuous dark web monitoring alerts you when we find leaked credentials or session tokens for your company.