Target stores hit by data breach affecting 40 million cards
cbc.ca
cbc.ca
https://corporate.target.com/discover/article/Important-Noti...
CVV/CSC, eh? The whole point of CSC is it should be non-stored and therefore much harder to steal than the CC#, right? Apparently that didn't work. Has CSC accomplished anything other than giving users more random-looking numbers they have to enter in online forms?
This leads me to conclude that either Target's software architecture is completely brain dead and they're storing PINs and CVV2's somewhere, or that the attack somehow managed to get insinuated into the credit card authorization process. As someone who has worked with credit cards for many years, as well as with high level people within both Target and Wal Mart, it's easier to believe the latter than the former.
http://www.nbcnews.com/technology/massive-target-credit-card...
If so, that's an incredibly sophisticated attack considering the scope of the breach.
http://en.wikipedia.org/wiki/Card_security_code#Types_of_cod...
"Track data is the information encoded in Track 1 and 2 within the magnetic stripe on the back of a Visa card. This information is read by a merchant’s point-of-sale (POS) system. Some merchant POS systems improperly store this data post authorization. This is a violation of Visa Operating Regulations. Hackers are aware of this vulnerability and are targeting vulnerable POS systems to steal this information."
It seems chances are this data was grabbed at the time it was transmitted for authorization, not from being incorrectly stored.
It's bad enough that someone can buy a card reader and walk down a sidewalk and capture credit card data by just being within a few feet of someone.
I use it all the time. I use one with every single online merchant except Amazon and Newegg. It's also great for places that like to auto-bill. Or if you are worried they will charge without permission.
If you are going to get a credit card, get it with one of the few banks that offer these numbers.
It's also great for asking someone to buy something for you: Create a number with a dollar limit and have them tell the merchant the number. Small merchants usually have no problem with this.
Target says the data is limited to cards used in the U.S. during the last few weeks:
https://corporate.target.com/discover/article/Important-Noti...
A few years ago, the Target Visa card had actually pioneered a move toward chipped credit cards. My Target card was the only chipped credit card I had, though, and AFAIK even my local Target stores were never equipped with chip-reading card readers. When my card expired, the replacement didn't have a chip.
It bothers me very much to realize that even though there was nothing I reasonably could have done to protect myself (except avoid credit cards entirely), this will ultimately be my problem to deal with. Not Target's problem. Not really. Not in the same way that it's mine.
I'm expected to "take... steps ... to protect [myself] against potential misuse of [my] credit and debit information." [1]
I realize that this is just the way the system works, but why does it work that way? The credit card system, instead of making the investments necessary to really secure credit card transactions, has externalized much of the tricky fraud-detection work onto the card users.
[1] https://corporate.target.com/discover/article/Important-Noti...
Yeah, those 40 million CCs accessed? Screw those people. The multi-million corp is the one who will really suffer....
It would seem to me that if you can't secure the data, you shouldn't keep it (which is the reason I use stuff like Stripe . I don't want to see the card number).
So I wonder if Red Card customers had their debit information stolen too....
I'm wondering what percentage of transactions were affected. Is 40 million 90%? 50%? There's no way to tell. It'd be nice if we knew whether or not to report it to the bank.
On the flip side, there are ways stores can catch this thing offline as well. Good in-store security and employee training to prevent skimmers or modified POS systems, etc. Without more details on how this breech happened, it's only guesses. I can feel their pain, but I don't know exactly how sorry I feel for them without knowing how preventable this attack could have been.
[1] http://www.forbes.com/sites/kashmirhill/2012/02/16/how-targe...
[2] Personal anecdote alert: Target once had an in-house captive brand (not a Target brand, but a brand available in no other store) of "oven bakeware" that didn't even meet the Uniform Commercial Code warranty of merchantability, as it would shatter if you used it in an oven to bake something. We found that out just before a meal when we were all hungry. The local store gave us all kinds of run-around about simply refunding our money for the defective product. That was ill-timed for Target, as one of my wife's students had just given us a gift certificate for Sam's Club, and we discovered that the much-maligned Sam's Club is better about returns and about customer service in general than Target. We have shifted THOUSANDS of dollars a year from Target, my home-town store I grew up with, to Sam's, the store everyone is inclined to decry, in the years since then. When a store sells a defective product and doesn't make that right, I don't give it a lot of second chances. (My sister's former job at Target was to be a buyer, and she thought that if a Target buyer screws up and purchases a bad product, Target should make that right, period.)
By contrast, I recently bought what was labeled as an "Epson ink-jet printer cartridge" through a third-party seller on Amazon, and when the product arrived it was labeled "Not an OEM product," and plainly wasn't identical to an actual Epson printer cartridge. I contacted Amazon about the purchase, and an Amazon representative said my money would be refunded and I didn't have to return the product. That is the way to use big data to build a better customer experience--Amazon could verify how the product was labeled on its site, and perhaps had another customer complain to verify that I wasn't making this up. Amazon consistently treats me like my user experience is more important that Amazon's next-quarter bottom line, and that builds immense customer loyalty for me.
They give you 5% off your purchase when you use the card. I consider it a fair trade in value given how much I spend there.
That "intrusive" tracking...I don't know if I feel the same. You're in their store. If they choose to watch how you shop there, you can stay or you're free to walk. They can't forcibly drop items into my basket...yet. If I choose to buy something personal that I feel Target shouldn't remember or relay to others, I'll pay cash.
http://www.forbes.com/sites/kashmirhill/2012/02/16/how-targe...
It is not ok for a retail company to profile your underage daughter, find out that she is probably pregnant (before you do!) and then do targeted advertisement. That is wrong and more than a little creepy.
They've since stopped sending pure "baby" coupons and instead mix those in with other coupons to avoid the creepy factor.
The pregnant teenager outlier certainly made for an interesting and headline-worthy story. Hopefully future big data projects like this put a bit more thought into the human side of the equation, but never count on it I suppose.
At an in-person store, I expect to develop a reputation with people who work there if I shop there often enough to recognize the customer service staff by sight (as I formerly did at our local Super Target). I didn't establish this context up above in my original comment, but I actually began shopping at the local Super Target three days before its official grand opening. (The grand opening was on a Sunday, but the store was open for business the Thursday before.) I bought a TV set (we had just returned to the United States from overseas, and didn't yet have a TV) and some other items from a newly hired cashier. During my conversation with the cashier (partly in Chinese, as I could see she was Chinese) the cashier was distracted, and DIDN'T RING UP the TV. So I got home, and my wife looked at the receipt and said, "How did you spend so little when you just got a TV?" We realized the TV wasn't listed on the receipt. So the next day I took the TV box with its store barcodes and my receipt to the customer service desk, and apologized for walking out of the store without paying for the TV, and asked the customer service staff to ring up the TV so that I could pay for it. The customer service staff were amazed (even here in the honest upper Midwest) that I came back to the store to incur that bill. But I wouldn't think of doing otherwise. I was a little worried that the new cashier would get in trouble for that mistake, but in fact she continued to work at that Target store for at least a year afterward, so the company evidently just treated that as a human-error mistake.
After that we shopped at our local Super Target ALL THE TIME. It's a comfortable walking distance from our house, and our children learn to navigate our neighborhood in large part by taking that walk. But a few years later, new management at Target became more responsive to outside shareholders and a bean-counter mentality took over, and customer service degraded badly. That's when I chanced to purchase the "oven bakeware" that shatters if you put it in an oven to bake something. We never did get our money back on that defective product, and the hassle we received at the same customer service desk, with people we knew by sight looking on, made us feel like thieves while we were asking for legitimate customer recourse under the Uniform Commercial Code. You see, I was demonstrably NOT a thief--I was the guy who had brought the TV box back to the store specifically so that I would be billed for it. If I can't develop a reputation for honesty by being honest at the local store where I shop the most, then their corporate policies can go take a flying leap while I take my business elsewhere. Anyone in the retail business has to provide good customer service as Job One. That's how retail is done. (My sister, if I may be allowed to repeat myself, knows that from when she worked at Target.) So if the company tracking doesn't work to my benefit, I'm out of there.
I thought an important part of the "members only" business model was that they pioneered exactly the sort of tracking you mention. My understanding was that at Costco and BJ's and Sam's Club, you're required to present your membership card even if you're paying cash. Perhaps I'm mistaken.
I've always been pleasantly surprised what good luck I've had returning things at all the big-box stores: Wal-Mart (which I mostly avoid these days), Target, Home Depot, Lowe's, etc. I wonder if it's a regional thing. It may help that I generally pay with a credit card, so I'm just asking for credit, not cash.
Of course, today, it sounds like that habit is biting me in the ass.
I just want to mention something about Sam's Club here. I've asked for a Sam's Club membership for the past two Christmases, and it's been so helpful. I get boneless, skinless chicken breast for $2/lb there (!), which is about half as much as my local Publixes. Just about everything is absurdly cheap and still the same brand/quality as anywhere else, you just have to buy more of it.
Since shopping at Sam's Club, I eat way healthier than I ever have in my life - I eat a ton of vegetables for instance, just because I like them - and I still manage to hit my high caloric and macronutrient requirements for my diet/training program (which are pretty strict, can be crazy expensive), all for about $5/day.
I can't recommend them enough.
I didn't take a ticket and instead swiped my CC to get into the lot. They repeatedly mentioned to don't lose your card since the day I left is tagged to it (I assume).
Given the chaos of this, I probably won't even get my new card until I'm back from vacation.
Does anyone know if all I need is another card with my name on it or if I can just allow for 30-60 minutes of searching through records to locate my original swipe in?
Also, PCI Compliance - personal information should not be stored unencrypted when at rest or when being transferred.
All joking aside, this isn't good. Does this mean a lot of other stores are in the danger zone as well? I know a lot of stores use the same software to run their everything.
It's been 6 years since I've worked there, but at the time everything was pretty much custom. The original system was created in 1993 I believe, since then there's been so many things built on top of it I can't image how they'd replace it.
The type of data stolen — also known as “track data” —
allows crooks to create counterfeit cards by encoding the
information onto any card with a magnetic stripe.
So it's not just the credit card numbers, but it's the full magstripe that was read and transmitted as-is to some central location where it was lifted. Debit cards and PINs, too, presumably.Downside of single (exploited) mistake in bitcoin wallet management: total loss of value.
...is a lot less damage than 40 million exposed credit cards
Getting my credit card details stolen is going to be less damaging than all but the smallest wallet thefts.
Ignoring the absurd interest rates, fees, insurance that cc companies charge...you assume that credit card/debit card theft costs are never passed on to the consumers