Payment systems at Saks Fifth Avenue and Lord & Taylor stores breached; credit card data of 5M+ customers allegedly stolen
Context & Ripple Effects
This is the latest entry in a long line of point-of-sale intrusions at major retailers: Staples detailed how attackers hit 115 stores' POS systems and 1.16M payment cards back in 2014, and the pattern has since repeated across grocery, fuel, and hospitality chains.
What distinguishes the Saks Fifth Avenue and Lord & Taylor report is scale and sourcing — Gemini Advisory alleges card data of 5M+ customers was taken from store payment systems, putting it in the same tier as Dixons Carphone's 5.9M-card breach disclosed months later.
First-order effects
- Card issuers face immediate reissuance and fraud-monitoring costs on potentially millions of Saks and Lord & Taylor accounts, while affected customers bear the disruption of replacement cards and disputed charges.
Second-order effects
- Luxury retail peers like Neiman Marcus — which separately notified 4.6M customers after its own breach — now operate under heightened scrutiny, as each large POS incident raises the reputational bar for the whole segment.
- The breach strengthens the case for chip-and-PIN migration: Dixons Carphone's finding that only its non-chip cards were compromised gives issuers and merchants a concrete argument for accelerating EMV rollout at the register.
Third-order effects
- If POS malware keeps yielding multi-million-card hauls across retail and food service — from Staples to Hy-Vee's pumps and restaurants — payment security shifts from a merchant IT concern to a compliance mandate, with liability rules increasingly pushing breach costs onto whichever party lags on chip adoption.
The trend: Point-of-sale breaches are becoming a recurring structural cost of card-present retail, steadily forcing the industry toward chip-based authentication and tighter liability allocation.