Saks Fifth Avenue and Lord & Taylor are among the most recognizable names in retail, but they became unwilling additions to a growing list of major businesses hit by cyberattacks. Their parent company, Hudson’s Bay Company, confirmed that point-of-sale (PoS) systems across dozens of locations had been compromised, resulting in the potential exposure of payment card data for millions of customers. The incident is a stark reminder that no business is immune to cybercrime and that proactive security and compliance measures are essential for protecting both customers and operations.
Details about the Attack
One distinctive feature of the Saks and Lord & Taylor breach was that it was not only a PoS breach. Instead, the hackers took over the network to gain access to confidential financial information. In these types of attacks on major retailers, hackers gain access to the network when privileged accounts are compromised. Traditionally, these cyber thieves gain access through phishing attacks, steal privileged information, and elevate their privileges while moving through the network. The end goal for many of these attackers is the PoS system, where they can steal information from debit and credit cards.
How to Prevent PoS Breaches
Retailers do not have to stand idly by until they become the newest victims of PoS attacks. CISA’s guidance on point-of-sale malware outlines several steps businesses can take to reduce the likelihood of falling victim to a cyberattack:
- Use EMV or Chip-and-Pin Technology – The latest chip-enabled cards prevent privileged information about payment cards from being exposed. Replacing outdated magnetic strip readers with newer chip-enabled technology can protect against attackers gaining access to this information.
- Close Security Gaps – Attackers often gain access to PoS systems through compromised employee credentials. Retail networks should be secure and separate from the rest of the network. Additionally, retailers can automate credential vaulting and monitor access to prevent these cyberattacks. A thorough network risk assessment can uncover those gaps before attackers do.
- Require Multi-Factor Authentication – Implementing multi-factor authentication on privileged accounts adds a critical layer of protection against unauthorized access. Pairing MFA with managed detection and response gives your security team the real-time visibility needed to catch threats before they escalate.
Protect Your Business Before the Next Breach Strikes
The Saks and Lord & Taylor attack is a sobering case study in what happens when security gaps go unaddressed. Cybercriminals operated inside the company’s network for nearly a year before being detected, ultimately compromising all Lord & Taylor locations and 83 Saks Fifth Avenue stores. Businesses of every size face similar risks, and the consequences go well beyond financial loss: customer trust, brand reputation, and regulatory standing are all at stake.
If you are concerned that your business may be vulnerable to attack, talking with a qualified IT specialist is an important first step. WheelHouse IT can review your cybersecurity posture, assess your level of risk, and recommend and implement best practices to provide greater security across your network. To schedule a professional consultation, contact our Florida office at (954) 474-2204, our New York office at (516) 536-5006, or reach out to us online.



