The Customer is the Target at Target (Massive Breach)

Status
Not open for further replies.

cruelsister

Level 42
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,152
This story was broken today by the Wall Street Journal:

Target Corp. was hit by an extensive theft of its customers' credit-card and debit-card data over the busy Black Friday weekend, people familiar with the matter said, in what appears to be a brazen breach of a major retailer's information security.

The theft was national in scope and happened in stores, not online, and may have involved tampering with the machines customers use to swipe their cards when making purchases, the people said. The Secret Service is investigating the breach, a spokesman said, but wouldn't discuss details of the incident while the investigation is ongoing. Secret Service often investigates significant hacks of credit-card data, as part of its mission is to safeguard the country's financial infrastructure and payment systems. Target didn't respond to requests for comment.

It is believed that the breach affected roughly 40,000 card devices at store registers, which could mean that millions of cardholders could be vulnerable, according to the people familiar with the incident. They also warned that details could change significantly as the investigation proceeds. The discount chain has 1,797 stores in the U.S. and another 124 in Canada.

The apparent breach occurred during the period when Americans kick off their holiday shopping and store traffic is around its highest of the year. Retailers try to lure shoppers to stores on Black Friday with "door buster" deals and overnight hours that often draw big crowds. Retailers try to lure shoppers to stores on Black Friday with "door buster" deals and overnight hours that often draw big crowds. The breach may have gone into the Monday after Thanksgiving, one of the people said.

The thieves gained access to data that is stored on the magnetic stripe on the back of the credit and debit cards, according to the people familiar with the breach. The stripe contains data that is valuable for making counterfeit cards, such as account numbers and expiration dates, but it wasn't immediately known which data was vulnerable. Hackers typically aim to sell such information in bulk on the black market to people who use it to produce fake credit or debit cards. Crime rings can use the fake cards to buy gift cards from major retailers and convert them eventually into cash, according to investigators and former U.S. officials.

One of the biggest incidents to hit the industry took place in 2007, when thieves stole card numbers and personal data on up to 90 million cards belonging to people who had shopped at stores owned by TJX Cos., parent of T.J. Maxx, HomeGoods and other discount chains. In July, federal prosecutors unsealed criminal charges in an ongoing investigation of a group of people believed to have stolen more than 160 million credit and debit card numbers from companies including J.C. Penney Co. , 7-Eleven, Nasdaq OMX Group, JetBlue Inc. and others over several years. Dow Jones Inc., a unit of News Corp. and publisher of The Wall Street Journal, was among the companies affected.

http://online.wsj.com/news/articles/SB10001424052702304773104579266743230242538
 
Last edited:

cruelsister

Level 42
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,152
The cards are now starting to show up on Dump sites rescator and kaddafi (both "citizens" of the Lampeduza Republic). So far, out of the 40 million cards compromised it seems about 1.5 million are included in the current base. The price range is from about 19-45USD per card (payment by Credit Card not allowed- I wonder why?). Note that the CVV2 code (digits printed on the card itself and not included on the strip) were not compromised and as such can't be used on many Internet sites,

This breach was for Target, which operates in the USA and Canada. From what I understand the store and/or Bank Issuer involved are not pressing to rescind the compromised cards, so if any out there is or knows someone who is involved, please take matters in your own hands and void the CC (hopefully not a debit) soonest.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top