Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Nordstrom

Nordstrom Vendor Cyber Rating & Cyber Score

nordstrom.com

At Nordstrom, we empower our employees to set their sights high and blaze their own trails. This is a place where your success and growth are truly a result of your own efforts and achievements. Our teams are made up of motivated people who work hard to become leaders within the company, at all levels of the organization. These well-traveled paths show how hard work, loyalty, a competitive spirit and your unwavering commitment to the customer can take you and your career to new places. In addition to being a great place to have a career, we’re also committed to respecting the environment and supporting our communities. To learn more, check out NordstromCares.com. Interested in joining the Nordstrom team? See some of our


Nordstrom A.I CyberSecurity Scoring

Nordstrom
Company Information
Website:http://www.nordstrom.com
Employees number:47,449
Number of followers:625,159
NAICS:43
Industry Type:Retail
Homepage:nordstrom.com
Nordstrom Risk Score (AI oriented)
Between 0 and 549
logo
NordstromRetail
Updated:
03/04/2026
514/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Nordstrom Global Score (TPRM)
xxxx
logo
NordstromRetail
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Nordstrom
NordstromCritical
Current Score
514C (CRITICAL)
01000
5 incidents
-67 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
527Before Incident
MAY 2026
522Before Incident
APRIL 2026
518Before Incident
MARCH 2026
579Before Incident
Breach
18 Mar 2026Nordstrom
Okta, Nordstrom and Salesforce: Nordstrom's email system abused to send crypto scams to customers

Nordstrom Customers Targeted in Cryptocurrency Scam via Compromised Email System

512After Incident
CRITICAL-67
NOROKTSAL1773854168
Nordstrom Customers Targeted in Cryptocurrency Scam via Compromised Email System Nordstrom customers recently received fraudulent emails from the company’s legitimate marketing address ([email protected]), promoting a cryptocurrency scam disguised as a St. Patrick’s Day promotion. The messages promised to double any cryptocurrency sent to a specified wallet within two hours, creating a false sense of urgency to pressure recipients into acting quickly. The scam emails contained red flags, including a misspelled company name ("Normstorm") in the subject line, though the official sender address likely led some victims to overlook the deception. Nordstrom later confirmed the messages were unauthorized and warned customers that the company would never request cryptocurrency transactions. A follow-up email urged recipients to disregard the fraudulent offer. While it remains unclear how many customers were affected, some victims reportedly sent funds to the attacker’s wallet, which accumulated over $5,600 in cryptocurrency. According to sources, the breach stemmed from a compromise in Okta SSO and Salesforce Marketing Cloud, allowing threat actors to send the scam emails through Nordstrom’s official channels. This incident mirrors recent attacks on Betterment and GrubHub, which also exploited similar vulnerabilities to distribute crypto scams. Nordstrom, a major U.S. retailer with over $15 billion in annual revenue and millions of customers, has not publicly detailed the extent of the breach or its response beyond issuing customer warnings. The company is investigating the incident.
INCIDENT DETAILS -
TYPE
Phishing / Scam
MOTIVATION
Financial gain
IMPACT
Financial Loss: $5,600 (reportedly accumulated in attacker's wallet)Systems Affected: Email marketing system (Salesforce Marketing Cloud), Okta SSOOperational Impact: Unauthorized use of official email channels for fraudulent activityBrand Reputation Impact: Potential erosion of customer trust due to fraudulent emails from official channels
FEBRUARY 2026
577Before Incident
JANUARY 2026
573Before Incident
DECEMBER 2025
570Before Incident
NOVEMBER 2025
566Before Incident
OCTOBER 2025
562Before Incident
SEPTEMBER 2025
558Before Incident
AUGUST 2025
691Before Incident
JULY 2025
550Before Incident
FEBRUARY 2025
771Before Incident
Breach
06 Feb 2025Nordstrom
Nordstrom, KFC, Foh&Boh, Taco Bell and Hyatt Grand: Hiring platform serves users raw with 5.4 million CVs exposed

Hiring Platform Foh&Boh Exposes 5.4 Million Job Seekers’ Resumes in Unsecured AWS Bucket

524After Incident
CRITICAL-247
NORKFCFOHTACHYA1769001351
Hiring Platform Foh&Boh Exposes 5.4 Million Job Seekers’ Resumes in Unsecured AWS Bucket A major data exposure incident has left the personal details of millions of job seekers vulnerable after U.S.-based hiring and onboarding platform Foh&Boh accidentally left an AWS S3 bucket unsecured, containing 5.4 million files primarily CVs and resumes. The breach, discovered by the Cybernews research team, exposed sensitive applicant information, including work history, contact details, and personal identifiers, which could be exploited for identity theft, phishing attacks, and financial fraud. Foh&Boh serves high-profile clients in the restaurant, hotel, and retail industries, including Taco Bell, KFC, Omni Hotels & Resorts, Nordstrom, and Hyatt Grand. The exposed data could allow cybercriminals to craft highly targeted phishing emails, referencing specific job applications or career details to deceive victims into revealing financial information or installing malware. Researchers warned that attackers might also use the data to open fraudulent bank accounts, apply for credit, or launch synthetic identity scams, particularly targeting individuals in vulnerable financial situations. The unsecured bucket was closed after multiple attempts to contact Foh&Boh, but the extent of unauthorized access remains unclear. The incident underscores the risks of misconfigured cloud storage, with experts recommending stricter access controls, encryption, and log reviews to prevent similar exposures. This breach follows another recent incident involving Luxshare, a key Apple supplier, where a ransomware group allegedly stole confidential data from Apple, Nvidia, and LG. The Foh&Boh leak highlights the growing threat of resume-based cyberattacks, where attackers leverage personal data to bypass security measures and exploit job seekers.
INCIDENT DETAILS -
TYPE
Data Exposure
MOTIVATION
Opportunistic (unauthorized access due to misconfiguration)
IMPACT
Data Compromised: 5.4 million files (CVs/resumes)Systems Affected: AWS S3 bucketBrand Reputation Impact: High (exposure of sensitive job seeker data)Legal Liabilities: Potential (regulatory violations, identity theft risks)Identity Theft Risk: High
DATA BREACH
CVsResumesWork historyContact detailsPersonal identifiersNumber Of Records Exposed: 5.4 million filesSensitivity Of Data: High (personally identifiable information)PDFDOCDOCX (assumed)Personally Identifiable Information: Yes
Breach
06 Feb 2025Nordstrom
Foh&Boh, KFC, Nordstrom, Hyatt Grand and Omni Hotels & Resorts: Hiring platform serves users raw with 5.4 million CVs exposed

Millions of Job Seekers’ Resumes Exposed in Foh&Boh Data Breach

524After Incident
CRITICAL-247
FOHKFCNORHYAOMN1769001235
Millions of Job Seekers’ Resumes Exposed in Foh&Boh Data Breach A major data exposure incident involving Foh&Boh, a U.S.-based hiring and onboarding platform for restaurants, hotels, and retailers, has left 5.4 million files primarily CVs and resumes publicly accessible via an unsecured AWS bucket. The breach, discovered by the Cybernews research team, exposed sensitive personal details that job applicants typically share with employers, including work history, contact information, and professional references. The platform serves high-profile clients such as Taco Bell, KFC, Omni Hotels & Resorts, Nordstrom, and Hyatt Grand, raising concerns about the potential misuse of the leaked data. While the dataset was secured after multiple attempts to contact Foh&Boh, the exposure could have enabled targeted phishing attacks, identity theft, and financial fraud. Researchers warned that cybercriminals could exploit the stolen information to craft highly personalized phishing emails, referencing specific job details or career interests to deceive victims. The data could also be weaponized for synthetic identity fraud, allowing attackers to open fraudulent bank accounts or apply for credit under victims’ names. Additionally, scammers might target financially vulnerable individuals with "get-rich-quick" schemes or impersonate past employers to extract further sensitive information. The incident underscores the risks of misconfigured cloud storage, with experts recommending stricter access controls, encryption, and retrospective log reviews to prevent unauthorized access. While the bucket is no longer publicly accessible, the long-term impact on affected job seekers remains unclear.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: 5.4 million files (CVs and resumes)Systems Affected: AWS bucketBrand Reputation Impact: Potential reputational damage to Foh&Boh and its clientsIdentity Theft Risk: High (synthetic identity fraud, financial fraud)
DATA BREACH
CVsResumesNumber Of Records Exposed: 5.4 million filesSensitivity Of Data: High (work history, contact information, professional references)Personally Identifiable Information: Yes (contact information, work history, professional references)
Breach
06 Feb 2025Nordstrom
Foh&Boh, Nordstrom, Hyatt Grand and Omni Hotels & Resorts: Hiring platform serves users raw with 5.4 million CVs exposed

Hiring Platform Foh&Boh Exposes 5.4 Million Job Seekers’ Resumes in Unsecured AWS Bucket

524After Incident
CRITICAL-247
FOHNORHYAOMN1769001286
Hiring Platform Foh&Boh Exposes 5.4 Million Job Seekers’ Resumes in Unsecured AWS Bucket A major data exposure incident has left the personal details of millions of job seekers vulnerable after U.S.-based hiring platform Foh&Boh accidentally left an AWS S3 bucket unsecured, containing 5.4 million files, primarily CVs and resumes. The breach, discovered by the Cybernews research team, exposed sensitive applicant information including work history, contact details, and personal identifiers making individuals susceptible to targeted phishing, identity theft, and financial fraud. Foh&Boh, which serves high-profile clients such as Taco Bell, KFC, Nordstrom, Omni Hotels & Resorts, and Hyatt Grand, failed to restrict public access to the storage bucket. While the dataset was later secured following multiple contact attempts by researchers, the exposure raises concerns about unauthorized access by malicious actors. Attackers could exploit the leaked data to craft highly personalized phishing emails, impersonate past employers, or launch scams targeting financially vulnerable individuals. The breach also heightens risks of identity theft, with cybercriminals potentially using the stolen details to open fraudulent bank accounts or apply for credit under victims’ names. Researchers warned that the incident could lead to synthetic identity fraud, where attackers combine real and fabricated information to create new, fraudulent identities. This follows another recent breach involving Luxshare, a key Apple supplier, where a ransomware cartel allegedly stole confidential data from Apple, Nvidia, and LG, threatening to leak it unless demands were met. The Foh&Boh incident underscores the persistent risks of misconfigured cloud storage, a common yet preventable security failure. No official statement from Foh&Boh has been released at this time.
INCIDENT DETAILS -
TYPE
Data Exposure
IMPACT
Data Compromised: 5.4 million files (CVs and resumes)Systems Affected: AWS S3 bucketBrand Reputation Impact: YesIdentity Theft Risk: Yes
DATA BREACH
CVsResumesWork historyContact detailsPersonal identifiersNumber Of Records Exposed: 5.4 million filesSensitivity Of Data: HighPDFDOCDOCXPersonally Identifiable Information: Yes
OCTOBER 2018
784Before Incident
Breach
09 Oct 2018Nordstrom
Nordstrom, Inc.

Nordstrom Data Breach

716After Incident
HIGH-68
NOR609072725
On November 5, 2018, the California Attorney General reported a data breach involving Nordstrom, Inc. The breach occurred on October 9, 2018, due to improper handling of employee data by a contract worker, potentially affecting names, Social Security numbers, and other personal information. No customer data was impacted, and the company has taken measures to prevent future incidents.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
NamesSocial Security numbersOther personal information
DATA BREACH
NamesSocial Security numbersOther personal informationSensitivity Of Data: HighPersonally Identifiable Information: Yes

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Nordstrom ?
?
What was Nordstrom's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Nordstrom's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Nordstrom's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Nordstrom's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Nordstrom's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Nordstrom's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Nordstrom's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Nordstrom's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Nordstrom's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Nordstrom's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Nordstrom's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Nordstrom's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Nordstrom ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Nordstrom's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?