Page 1 of 2 1 2 LastLast
Results 1 to 20 of 35
  1. #1
    BG Content
    Join Date
    Oct 2005
    Posts
    69,670
    BG Level
    10
    FFXIV Character
    Six Souls
    FFXIV Server
    Gilgamesh
    FFXI Server
    Quetzalcoatl
    WoW Realm
    Malorne
    Blog Entries
    9

    Target stores hacked, estimated 70-110 million customers affected

    Yes this is old news seeing as the hack happened between November 27th & December 15th. But no one ever made a thread for this. Initially Target released a statement that 40 million customers were affected;

    The hackers who attacked Target Corp and compromised up to 40 million credit cards and debit cards also managed to steal encrypted personal identification numbers (PINs), according to a senior payments executive familiar with the situation.

    One major U.S. bank fears that the thieves would be able to crack the encryption code and make fraudulent withdrawals from consumer bank accounts, said the executive, who spoke on the condition of anonymity because the data breach is still under investigation.

    Target spokeswoman Molly Snyder said "no unencrypted PIN data was accessed" and there was no evidence that PIN data has been "compromised." She confirmed that some "encrypted data" was stolen, but declined to say if that included encrypted PINs.

    "We continue to have no reason to believe that PIN data, whether encrypted or unencrypted, was compromised. And we have not been made aware of any such issue in communications with financial institutions to date," Snyder said by email. "We are very early in an ongoing forensic and criminal investigation."

    The No. 3 U.S. retailer said last week that hackers stole data from as many as 40 million cards used at Target stores during the first three weeks of the holiday shopping season, making it the second-largest data breach in U.S. retail history.

    Target has not said how its systems were compromised, though it described the operation as "sophisticated." The U.S. Secret Service and the Justice Department are investigating. Officials with both agencies have declined comment on the investigations.

    The attack could end up costing hundreds of millions of dollars, but it is unclear so far who will bear the expense.

    While bank customers are typically not liable for losses because of fraudulent activity on their credit and debit cards, JPMorgan Chase & Co and Santander Bank said they have lowered limits on how much cash customers can take out of teller machines and spend at stores.

    The unprecedented move has led to complaints from consumer advocates about the inconvenience it caused from the late November Thanksgiving holiday into the run-up to Christmas. But sorting out account activity after a fraudulent withdrawal could take a lot more time and be worse for customers.

    JPMorgan has said it was able to reduce inconvenience by giving customers new debit cards printed quickly at many of its branches, and by keeping branches open for extended hours. A Santander spokeswoman was not available for comment on Tuesday.

    Security experts said it is highly unusual for banks to reduce caps on withdrawals, and the move likely reflects worries that PINs have fallen into criminal hands, even if they are encrypted.

    "That's a really extreme measure to take," said Avivah Litan, a Gartner analyst who specializes in cyber security and fraud detection. "They definitely found something in the data that showed there was something happening with cash withdrawals."

    Spoiler: show
    While the use of encryption codes may prevent amateur hackers from obtaining the digital keys to customer bank deposits, the concern is the coding cannot stop the kind of sophisticated cyber criminal who was able to infiltrate Target for three weeks.

    Daniel Clemens, CEO of Packet Ninjas, a cyber security consulting firm, said banks were prudent to lower debit card limits because they will not know for sure if Target's PIN encryption was infallible until the investigation is completed.

    As an example of potential vulnerabilities in PIN encryption, Clemens said he once worked for a retailer who hired his firm to hack into its network to find security vulnerabilities. He was able to access the closely guarded digital "key" used to unscramble encrypted PINs, which he said surprised his client, who thought the data was secure.

    In other cases, hackers can get PINs by using a tool known as a "RAM scraper," which captures the PINs while they are temporarily stored in memory, Clemens said.

    The attack on Target began on November 27, the day before the Thanksgiving holiday and continued until December 15. Banks that issue debit and credit cards learned about the breach on December 18, and Target publicly disclosed the loss of personal account data on December 19.

    On December 21, JPMorgan, the largest U.S. bank, alerted 2 million of its debit cardholders that it was lowering the daily limits on ATM withdrawals to $100 and capping store purchases with their cards at $500.

    On Monday, the bank partly eased the limits it had imposed on Saturday, setting them at $250 a day for ATM withdrawals and $1,000 a day for purchases. (The usual debit card daily limits are $200 to $500 for cash withdrawals and $500 for purchases, a bank spokeswoman said last week.)

    On Monday, Santander - a unit of Spain's Banco Santander - followed suit, lowering the daily limits on cash withdrawals and purchases on Santander and Sovereign branded debit and credit cards of customers who used them at Target when the breach occurred. Santander did not disclose the new limits, but said it was monitoring the accounts and issuing new cards to customers who were affected.

    The largest breach against a U.S. retailer, uncovered in 2007 at TJX Cos Inc, led to the theft of data from more than 90 million credit cards over about 18 months.
    http://www.businessinsider.com/targe...-cards-2013-12

    But this week the total had been increased to 70 million minimum and up to as many as 110 million.

    Target said 70 million customers were affected by a data breach at its stores between Nov. 27 and Dec. 15, an increase from a previous estimate of 40 million customers.

    The 70 million customers may be separate from the initial 40 million customers, the company said, though there may be some overlap.

    The latest figure came during Target's ongoing forensic probe, which revealed that "certain guest information — separate from the payment card data previously disclosed — was taken during the data breach," according to a press release from the company. Target says the theft is not a new breach. The stolen information includes names, mailing addresses, phone numbers or email addresses for those 70 million or so customers.

    A Target rep told Mashable that the affected customers will be notified via email within the next week. She said much of the compromised — including names, addresses and some phone numbers — were publicly available. However, some — like emails and wireless phone numbers — were not.

    Affected customers will have zero liability for the cost of any charges incurred during the breach. "I know that it is frustrating for our guests to learn that this information was taken and we are truly sorry they are having to endure this,” Gregg Steinhafel, chairman, president and CEO of Target said in the release. “I also want our guests to know that understanding and sharing the facts related to this incident is important to me and the entire Target team.”

    The company also announced that its fourth quarter results have been hurt by the breach. Target now expects fourth-quarter earnings per share of $1.20 to $1.30, compared to the previous estimate of $1.50 to $1.60.

    Eric Chiu, president and co-founder of HyTrust, a cloud computing firm, says the breach will have a "massive" impact on consumers for some time, perhaps even years. "[The hackers] aren't going to go out and buy a boat with your credit card right away," he says. "Maybe they'll start small or wait for a while."

    It's unclear, however, how many people will be affected in the short term. Though 40 million credit cards were involved in the security breach, that doesn't necessarily mean that all 40 million cards will need to be replaced. Moreover, if thieves succeed in using the stolen credit cards, consumers will be reimbursed for those purchases.

    Perhaps a bigger threat comes from the names, e-mail addresses, physical addresses and phone numbers that have now been leaked. Cyber criminals can use such data for spear-phishing attacks, which use some personal information to trick users into clicking on a URL. Once they click, they might be enticed to enter password information or inadvertently download malware that could retrieve their personal information.

    For that reason, the up to one-third of the U.S. population affected by the breach should be on guard for phishing emails and fraudulent charges on their credit cards for some time. "Be very careful about what you click on," says Alan Kessler, CEO of cloud security firm Vormetric. "If you see something suspicious from your friends, notify them."

    David Kennedy , founder and principal security consultant for TrustedSEC, a security firm, says consumers should cancel their credit cards as well. Kennedy says that credit card companies aren't advocating such a solution because it will cost them a few dollars each to replace a card. "It's cheaper for them to not issue them," he says. A source close to one of the major credit card companies, meanwhile, says that the damage from the initial attack is likely to be well below the 40 million figure being discussed. Although that number of cards were potentially exposed to such a breach, the actual number of compromised attacks is likely to be much lower.

    Robert Siciliano, a McAfee online security expert, was also sanguine about the attack. "I don't worry about data breaches like this," he says. Siciliano also says Target probably did as much as it could to prevent being hacked. "What Target did to protect their data is pretty comprehensive," he says. "They didn't leave the door wide open." Like everyone else, though, Target has to deal with the fact that hackers are working around the clock to break into its system, Siciliano says. "The chance of your data being hacked is real. It's an advanced, persistent threat."

    Kennedy says now that hackers have made a big score on the target data — he estimates the take to be in the billions — that other retailers should be on their guard. "They smell blood in the water," Kennedy says. "This is just the beginning."

    Indeed, Brian Krebs whose Krebs on Security blog broke the Target story, thinks another retailer is in the crosshairs. "I think there's another one on the way," he says. "And it's going to be soon."
    http://mashable.com/2014/01/10/targe...n-data-breach/
    http://pressroom.target.com/news/tar...al-performance

    Through many places there is currently a month wait on receiving replacement credit/debit cards. For debit users, a temp fix of changing you pin number is recommended.

  2. #2
    You wouldn't know that though because you've demonstrably never picked up a book nor educated yourself on the matter. Let me guess, overweight housewife?
    Join Date
    Mar 2006
    Posts
    22,829
    BG Level
    10
    FFXIV Character
    Allyra Arianos
    FFXIV Server
    Sargatanas
    WoW Realm
    Windrunner

    Ugh, this is such a pain in the neck. I've been watching my charges and so far I have been unaffected. But I guess I need to replace everything, which fucking sucks since that means I gotta somehow do it for my husband too who only has Sunday's off atm (which is when banks are closed.)

  3. #3
    Han Cholo
    Sweaty Dick Punching Enthusiast

    Join Date
    Oct 2006
    Posts
    7,447
    BG Level
    8
    FFXIV Character
    Azor A'hai
    FFXIV Server
    Sargatanas

    Yup, the bank I work at is open 7 days a week, so when this happened about 90% of the people that came in were here to hot card their cards, and get instant issue debit card replacements. It sucked balls, and we are still getting people with these letters to replace them. If they hit another big retailer soon.. fml.

  4. #4
    Wesley Crusher 4 Lyfe!
    Skywalker's Severed Hand

    Join Date
    Apr 2005
    Posts
    733
    BG Level
    5
    FFXIV Character
    Psychodwarf Ironflute
    FFXIV Server
    Hyperion
    FFXI Server
    Bahamut

    I was affected early December. It sucks, but it was easy enough to fix. New card, charge reversed, no trouble since.

  5. #5
    Ridill
    Join Date
    Jul 2008
    Posts
    11,255
    BG Level
    9

    I wonder if Target was warned multiple times like Snapchat was.

  6. #6
    Yoshi P
    Join Date
    Nov 2006
    Posts
    5,081
    BG Level
    8
    FFXI Server
    Quetzalcoatl
    WoW Realm
    Proudmoore

    People may be tempted to think that no one would bother pulling his credit card out of the pile with all the security, etc. but this is serious.

    When Sony servers were hacked and sony got the payment details stolen, they used my credit card twice on 2 $1 items from Wal-mart to check and see if the card was working.

    After they've verified that the card was good, they attempted to make a purchase of $2000~from California on paint, etc. Bank caught the fraud due to the geographical proximity of the usage.

    If i was in Cali and previously did purchases there the transaction would go through. I should say I was just lucky.

    So...yeah, check your statements.

  7. #7
    Han Cholo
    Sweaty Dick Punching Enthusiast

    Join Date
    Oct 2006
    Posts
    7,447
    BG Level
    8
    FFXIV Character
    Azor A'hai
    FFXIV Server
    Sargatanas

    Visa usually calls the card holder when transactions out of state are going on, if they can't verify it was them attempting it via phone call, they will hot card your card.

    It's insane to think they can just steal all that data and upload it onto newly printed cards, one of the big negatives of the instant issue machine IMO.

  8. #8
    She Shoots For The Stars
    Join Date
    Aug 2009
    Posts
    1,642
    BG Level
    6
    FFXIV Character
    Elizara Paksenarrion
    FFXIV Server
    Excalibur
    FFXI Server
    Quetzalcoatl

    One of my brothers and my other brother's wife (Naming no names) got bit by this, no charges yet. I have a mild beef against Chase (has to do with how they handled some stuff after my mom's death) but they sent them both new cards soon as they knew, which is good. But yeah. Don't take this lightly and keep a eye on any card you used at Target, not to mention if you haven't, get new cards asap.

    This makes me want to use cash more for stuff. ^^

  9. #9
    Banned.

    Join Date
    Aug 2007
    Posts
    2,547
    BG Level
    7

    My credit union sent me a new card without even asking for one because they apparently checked if people had used credit cards at Target. No weird charges or anything yet, just decided to send me a new card for my protection. Credit unions are pretty awesome.

  10. #10
    Like a boss yo
    Join Date
    Feb 2006
    Posts
    3,852
    BG Level
    7
    FFXI Server
    Odin
    WoW Realm
    Mal'Ganis

    USAA did the same for me. Sent me a new Mastercard. Stated Mastercard contacted them and that I had used my Debit/CC card there during the during of the theft.

    We normally use the Target check card instead of a normal CC though. No charges as of yet.

  11. #11
    Ridill
    Join Date
    Jul 2008
    Posts
    11,255
    BG Level
    9

    Last info I read a few weeks ago pointed to most likely an SQLi that allowed them access to the servers. That and their windows xp embedded systems probably didn't help that much.

  12. #12
    Pandemonium
    Join Date
    Feb 2010
    Posts
    7,653
    BG Level
    8
    FFXI Server
    Sylph

    That and their windows xp embedded systems probably didn't help that much.
    This. There are so many people unaware that XP support ends on April 8th. There are going to be a lot of hacked companies after that date who don't have the IT staff to updrade computers to 7. The sad thing is, most XP boxes will run 7 with a simple RAM upgrade. Hell, I put it on a Dimension 2350 the other day.

    A company the size of target should have already resolved this though. If I was CEO, the CIO would be walking out the door soon.

  13. #13
    Ridill
    Join Date
    Jul 2008
    Posts
    11,255
    BG Level
    9

    Quote Originally Posted by Buffy View Post
    This. There are so many people unaware that XP support ends on April 8th. There are going to be a lot of hacked companies after that date who don't have the IT staff to updrade computers to 7. The sad thing is, most XP boxes will run 7 with a simple RAM upgrade. Hell, I put it on a Dimension 2350 the other day.

    A company the size of target should have already resolved this though. If I was CEO, the CIO would be walking out the door soon.
    http://www.computerworld.com/s/artic...ures_for_years

    Don't worry, AV companies will still put out updates for it! lolololololololol

    It's going to be fun as hell to be in the NetSec field soon.

  14. #14
    Who's driving? Oh my God Bear is driving! How can that be??
    Join Date
    Sep 2008
    Posts
    5,882
    BG Level
    8
    FFXI Server
    Lakshmi

    Well it appears that this malware that was installed on POS terminals might be out in the wild because the Arts and Crafts store Michael's had a security breach

    http://money.cnn.com/2014/01/25/news...curity-breach/

    The interesting thing about this though is that some other companies might be going through the same thing, but have yet to publicly announce it.

  15. #15
    But I don't want my title changed
    Join Date
    Nov 2008
    Posts
    6,486
    BG Level
    8
    FFXIV Character
    Fievel Mousekewitz
    FFXIV Server
    Excalibur

    ffs, I went to Michaels for the first time in my life to get somebody a Christmas gift last month.

    Really hope I don't have to get another new card.

  16. #16
    You wouldn't know that though because you've demonstrably never picked up a book nor educated yourself on the matter. Let me guess, overweight housewife?
    Join Date
    Mar 2006
    Posts
    22,829
    BG Level
    10
    FFXIV Character
    Allyra Arianos
    FFXIV Server
    Sargatanas
    WoW Realm
    Windrunner

    Starting to feel the urge to go back to cash for awhile though.

    Which sucks 'cause I still wanna use my target card for the 5%...

  17. #17
    Ridill
    Join Date
    Jul 2008
    Posts
    11,255
    BG Level
    9

    http://securityaffairs.co/wordpress/...ood-faith.html

    They tracked down the author of Black-POS...fucking typos in that article though make it annoying to fucking read at times.


    23 year old teenager!!!

  18. #18
    But I don't want my title changed
    Join Date
    Nov 2008
    Posts
    6,486
    BG Level
    8
    FFXIV Character
    Fievel Mousekewitz
    FFXIV Server
    Excalibur

    That was nearly impossible to read, good lord.

  19. #19
    Who's driving? Oh my God Bear is driving! How can that be??
    Join Date
    Sep 2008
    Posts
    5,882
    BG Level
    8
    FFXI Server
    Lakshmi

    Sounds like that article was either fed through a translator or the writer speaks English as a second or third language.

    So the teen basically went on to say that he created the malware to test the security of POS terminals and sold it but stated that it wasn't his intent for it to be used maliciously?

  20. #20
    BG's #1 Hatsune Miku fan!
    Join Date
    Dec 2009
    Posts
    9,974
    BG Level
    8

    It continues..

    Neiman Marcus, the second high-profile retailer to reveal that it suffered a major data breach at its stores, said on Thursday that the credit and debit card information of 1.1 million shoppers could have been stolen by malicious software installed in its payment systems.

    In an update on the company's website, CEO Karen Katz said that malware was used between July 16 and Oct. 30 to collect shoppers' payment data. To date, Visa, MasterCard and Discover have notified the department store that approximately 2,400 unique customer payment cards used at its Neiman Marcus and Last Call stores were subsequently used fraudulently. ....
    http://www.cnbc.com/id/101358995

Page 1 of 2 1 2 LastLast

Similar Threads

  1. Massive Credit Card Hack 10 Million Accounts
    By Gokku in forum General Discussion
    Replies: 1
    Last Post: 2012-03-30, 15:53
  2. "Minding the Store" - premiering sunday at 10/9c o
    By Pauly_Shore in forum General Discussion
    Replies: 100
    Last Post: 2005-07-21, 14:05
  3. Forget Star Wars, this is Store Wars!
    By lesliecheung in forum General Discussion
    Replies: 4
    Last Post: 2005-05-27, 11:00
  4. SOE has 0 customer service support
    By Endo in forum General Discussion
    Replies: 5
    Last Post: 2004-12-19, 15:12