Newsletters
News & Information for Technology Purchasers NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
This ad will display for the next 20 seconds. Click for more information, or
Home Enterprise I.T. Cloud Computing Applications Hardware More Topics...
GET RECOGNIZED.
Let an ISACA® certification
elevate your career.

Register today and save
Network Security
DDoS Protection Powered By Verisign
Average Rating:
Rate this article:  
Analysts Say Target's Entire Network Breached

Analysts Say Target's Entire Network Breached
By Jennifer LeClaire

Share
Share on Facebook Share on Twitter Share on Linkedin Share on Google Plus

The fact that such a massive amount of additional data was comprised in the Target security breach provides security researchers a better picture of what has happened. Target’s whole network appears to have been compromised, not just the payment processing side.
 


Target has upped the estimates on its holiday data breach, raising the number of those affected to between 70 million and 110 million people. That’s about three times higher than the retailing giant’s initial projections of 40 million affected users.

“I know that it is frustrating for our guests to learn that this information was taken, and we are truly sorry they are having to endure this,” said Gregg Steinhafel, Target's chief executive. However, Target has still not disclosed how the breach occurred.

More Facts Needed

We caught up with Lamar Bailey, director of security research and development at TripWire, to get his take on the latest Target revelations. He told us everyone is talking about the increased numbers of customers affected by this breach but the number of accounts isn’t the real concern.

“The real concern is that that along with the account numbers and pins even more data was stolen including full names, phone numbers, physical and e-mail addresses. This disclosure indicated that the breach happened deeper in the network than originally thought and, as is often the case, we may not have the complete story yet,” Bailey said.

“Target is saying most of the data is ‘partial in nature,' but of the 70 million accounts that were breached how many had all their data exposed? All Target shoppers should be checking their credit reports and card statements for fraudulent accounts and charges. Everyone should assume everything but your DNA profile was stolen,” he added.

Entire Network Compromised?

Ken Westin, a security researcher at TripWire, told us this incident reflects the horrifying truth of today’s data breaches, the organizations affected rarely know they have been breached. Even when they do, he said, it takes a long time before they know the duration of the breach or the scope of the breach.

“The fact that such a massive amount of additional data was comprised provides security researchers a better picture of what has happened. Target’s whole [network] appears to have been compromised, not just the payment processing side,” Westin said.

“When a network is compromised it’s easy for an attacker to move laterally because internal security controls are generally much more lax. These attackers had weeks to move around within the Target network, it would be safe to assume their entire network was compromised as a result," he said.

Will It Get Worse?

From his perspective, Tyler Reguly, security research and development manager at TripWire, told us it definitely looks like we're talking about a multi-pronged attack considering 40 million credit and debit accounts and now 70 million individuals having had their data stolen.

“We know account data was due to a compromise at the point of sale level. If the personal data compromise happened in the same place, you really have to question Target's business practices and wonder why was this data stored at that level. It's more likely that this breach occurred elsewhere in their network, especially since it was referred to as a separate attack,” Reguly said.

“So the numbers are 70 million and 40 million with ‘some overlap’ but let's put those together, we're talking about potentially 110 million people having some portion of their data breached. If you apply the ‘some overlap,' then you're down to maybe 100 million, that's still a huge data breach. It will be interesting to know exactly what the final number is,” Reguly added.
 

Tell Us What You Think
Comment:

Name:

Jill:

Posted: 2014-01-11 @ 8:04am PT
There have been so many security and privacy breaches over the last two years. We should start to demand better security and privacy from companies. I have recently started to become interested in privacy (I'm a HUGE fan of Ravetree and DuckDuckGo). Hopefully Target will fix their system to allow for better security so their users privacy won't be compromised again.



Salesforce.com is the market and technology leader in Software-as-a-Service. Its award-winning CRM solution helps 82,400 customers worldwide manage and share business information over the Internet. Experience CRM success. Click here for a FREE 30-day trial.


 Network Security
1.   UPS Stores Hit by Data Breach
2.   Target Data Breach Cost: $148 Million
3.   Aruba Handles Black Hat with Aplomb
4.   Chinese Hackers Steal Patient Data
5.   FBI Cybersquad To Add Agents


advertisement
Aruba Handles Black Hat with Aplomb
Network firm sees 2,376 DoS attacks.
Average Rating:
UPS Stores Hit by Data Breach
Biz must adopt better security measures.
Average Rating:
Target Data Breach Cost: $148 Million
Better customer data protection needed.
Average Rating:


advertisement
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
UPS Stores in 24 States Hit by Data Breach
Big Brown has been breached. UPS said that about 105,000 customer transactions at 51 of its UPS Store locations in 24 states could have been compromised between January and August.
 
Cost of Target Data Breach: $148 Million Plus Loss of Trust
The now infamous Target data breach is still costing the company -- and its shareholders -- plenty. In fact, the retailing giant forecast the December 2013 incident cost shareholders $148 million.
 
Aruba Networks Handles Black Hat with Aplomb
It's not an easy job. Aruba Networks' task throughout the Black Hat USA conference in Las Vegas this month was to ensure thousands of attendees could connect without malicious attacks.
 

Enterprise Hardware Spotlight
Acer's New Desktop Box Rides the Chrome OS Wave
Filling out its Chrome OS line, Acer is following the introduction of a larger Chromebook line earlier this month with a new tiny $180 desktop Chromebox and also a smaller Chromebook.
 
Three New Lenovo PCs Aimed at Business Users
Businesses everywhere want computing solutions that do more for less money, and Lenovo has unveiled three new desktop PCs that offer solid computing at a budget-minded price.
 
Aruba Networks Handles Black Hat with Aplomb
It's not an easy job. Aruba Networks' task throughout the Black Hat USA conference in Las Vegas this month was to ensure thousands of attendees could connect without malicious attacks.
 

Mobile Technology Spotlight
Samsung, B&N Target Amazon with Nook Tablet
They've seen the enemy and it is Amazon. So Samsung and Barnes & Noble are teaming up to combat their common foe with a 7-inch tablet that blends Samsung’s tech, Nook’s content and e-reader platform.
 
Acer's New Desktop Box Rides the Chrome OS Wave
Filling out its Chrome OS line, Acer is following the introduction of a larger Chromebook line earlier this month with a new tiny $180 desktop Chromebox and also a smaller Chromebook.
 
Apple Stock Soars Ahead of iPhone 6 Launch
The imminent release of the iPhone 6 -- and maybe even an iWatch -- has sent Apple's stock soaring to new heights. Considering what else the firm could have up its sleeve -- the stratosphere may be the limit.
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Cloud Computing | Applications | Hardware | Mobile Tech | Big Data | Communications
World Wide Web | Network Security | Data Storage | CRM Systems | Microsoft/Windows | Apple/Mac | Linux/Open Source | Personal Tech
Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.