Newsletters
News & Information for Technology Purchasers NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
This ad will display for the next 20 seconds. Please click for more information, or scroll down to pass the ad, or Close Ad.
Home Enterprise I.T. Cloud Computing Applications Hardware More Topics...
Eliminate costly downtime!
Find out how with Free White Paper
& enter to win a Samsung Galaxy Note

www.apc.com
Data Storage
24/7/365 Network Uptime
Average Rating:
Rate this article:  
Analysts Say Target
Analysts Say Target's Entire Network Breached

By Jennifer LeClaire
January 10, 2014 1:57PM

    Bookmark and Share
The fact that such a massive amount of additional data was comprised in the Target security breach provides security researchers a better picture of what has happened. Target’s whole network appears to have been compromised, not just the payment processing side.
 



Target has upped the estimates on its holiday data breach, raising the number of those affected to between 70 million and 110 million people. That’s about three times higher than the retailing giant’s initial projections of 40 million affected users.

“I know that it is frustrating for our guests to learn that this information was taken, and we are truly sorry they are having to endure this,” said Gregg Steinhafel, Target's chief executive. However, Target has still not disclosed how the breach occurred.

More Facts Needed

We caught up with Lamar Bailey, director of security research and development at TripWire, to get his take on the latest Target revelations. He told us everyone is talking about the increased numbers of customers affected by this breach but the number of accounts isn’t the real concern.

“The real concern is that that along with the account numbers and pins even more data was stolen including full names, phone numbers, physical and e-mail addresses. This disclosure indicated that the breach happened deeper in the network than originally thought and, as is often the case, we may not have the complete story yet,” Bailey said.

“Target is saying most of the data is ‘partial in nature,' but of the 70 million accounts that were breached how many had all their data exposed? All Target shoppers should be checking their credit reports and card statements for fraudulent accounts and charges. Everyone should assume everything but your DNA profile was stolen,” he added.

Entire Network Compromised?

Ken Westin, a security researcher at TripWire, told us this incident reflects the horrifying truth of today’s data breaches, the organizations affected rarely know they have been breached. Even when they do, he said, it takes a long time before they know the duration of the breach or the scope of the breach.

“The fact that such a massive amount of additional data was comprised provides security researchers a better picture of what has happened. Target’s whole [network] appears to have been compromised, not just the payment processing side,” Westin said.

“When a network is compromised it’s easy for an attacker to move laterally because internal security controls are generally much more lax. These attackers had weeks to move around within the Target network, it would be safe to assume their entire network was compromised as a result," he said.

Will It Get Worse?

From his perspective, Tyler Reguly, security research and development manager at TripWire, told us it definitely looks like we're talking about a multi-pronged attack considering 40 million credit and debit accounts and now 70 million individuals having had their data stolen.

“We know account data was due to a compromise at the point of sale level. If the personal data compromise happened in the same place, you really have to question Target's business practices and wonder why was this data stored at that level. It's more likely that this breach occurred elsewhere in their network, especially since it was referred to as a separate attack,” Reguly said.

“So the numbers are 70 million and 40 million with ‘some overlap’ but let's put those together, we're talking about potentially 110 million people having some portion of their data breached. If you apply the ‘some overlap,' then you're down to maybe 100 million, that's still a huge data breach. It will be interesting to know exactly what the final number is,” Reguly added.
 

Tell Us What You Think
Comment:

Name:

Jill:

Posted: 2014-01-11 @ 8:04am PT
There have been so many security and privacy breaches over the last two years. We should start to demand better security and privacy from companies. I have recently started to become interested in privacy (I'm a HUGE fan of Ravetree and DuckDuckGo). Hopefully Target will fix their system to allow for better security so their users privacy won't be compromised again.



APC has an established a reputation for solid products that virtually pay for themselves upon installation. Who has time to spend worrying about system downtime? APC makes it easy for you to focus on business growth instead of business downtime with reliable data center systems and IT solutions. Learn more here.


 Data Storage
1.   VMware Rolls Out DR-as-a-Service
2.   Dropbox Rolls Out Business Service
3.   Fast Seagate 6 TB Drive for Data Center
4.   Green Data Centers Get Kudos
5.   Oracle Rolls Out Enhanced MySQL


advertisement
Dropbox Rolls Out Business Service
For long, slow move into the enterprise.
Average Rating:
Fast Seagate 6 TB Drive for Data Center
Can use 12 Gb/s SAS interface.
Average Rating:
Green Data Centers Get Kudos
Google, Facebook, Apple lead the way.
Average Rating:


advertisement
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
IBM Offers Security, Disaster Recovery as SoftLayer Service
New disaster recovery and security services for SoftLayer clients are being added by IBM. Big Blue said the new capabilities will speed cloud adoption by alleviating concern over business continuity.
 
How To Beat the Heartbleed Bug
Heartbleed headlines continue as IT admins scramble for answers no one has. Early reports of stolen personal data, including 900 social insurance numbers in Canada, are starting to trickle in.
 
After Heartbleed, OpenSSL Calls for More Support
The president of the OpenSSL Foundation says more support is needed from companies and governments that use its software so that it can better spot and fix flawed pieces of code such as Heartbleed.
 

Enterprise Hardware Spotlight
Vaio Fit 11A Battery Danger Forces Recall by Sony
Using a Sony Vaio Fit 11A laptop? It's time to send it back to Sony. In fact, Sony is encouraging people to stop using the laptop after several reports of its Panasonic battery overheating.
 
Continued Drop in Global PC Shipments Slows
Worldwide shipments of PCs fell during the first three months of the year, but the global slump in PC demand may be easing, with a considerable slowdown from last year's drops.
 
Google Glass Finds a Home in Medical Education, Practice
Google Glass may find its first markets in verticals in which hands-free access to data is a boon. Medicine is among the most prominent of those, as seen in a number of Glass experiments under way.
 

Mobile Technology Spotlight
Amazon 3D Smartphone Pics Leaked
E-commerce giant Amazon is reportedly set to launch a smartphone after years of development. Photos of the phone, which may feature a unique 3D interface, were leaked by tech pub BGR.
 
Zebra Tech Buys Motorola Enterprise for $3.45B
Weeks after Lenovo bought Motorola Mobility’s assets from Google for $2.91 million, Zebra Technologies is throwing down $3.45 billion for Motorola’s Enterprise business in an all-cash deal.
 
CTIA Caves, Volunteers Kill Switch Plan
After bucking against the concept of a smartphone kill switch, the CTIA just announced the “Smartphone Anti-Theft Voluntary Commitment” to thwart smartphone thefts in the U.S.
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Cloud Computing | Applications | Hardware | Mobile Tech | Big Data | Communications
World Wide Web | Network Security | Data Storage | Small Business | Microsoft/Windows | Apple/Mac | Linux/Open Source | Personal Tech
Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.