The breach of data from Target (along with Neiman Marcus and reportedly a few more) seems to be getting worse by the day. There are some things I find highly concerning.
First, some facts. #
- Attacks started on November 27, 2013 (just in time for Black Friday).
- The attack went unnoticed until December 15, 2013, over two weeks later.
- Hackers got names, addresses, email addresses, and phone numbers of 70 million people; 11GB of data total.
- Siphoned data has been sent to Russia and who knows where else from there.
- Attackers used a RAM scraper to capture un-encrypted data from point-of-sale systems after the credit card swipe, but before it was encrypted and sent to a central location for routing to the credit card companies.
- Target and Neiman Marcus both passed all annual compliance testing for their handling of credit card data by the credit card industry standard (PCI-DSS).
- A similar attack happened in 2005.
Why does this keep happening? #
The short answer is pretty simple, as disappointing as it is. The industry standard is subpar, retailers are too cheap to upgrade, and people are frequently reactive in nature. Now there’s something to react to, let’s see if it works.