News & Information for Technology Purchasers
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Enterprise I.T. Hardware Software Communications More Topics...
Computing
Average Rating:
Rate this article:  
Grocery Chain Data Breach Offers Lessons for CIOs Grocery Chain Data Breach Offers Lessons for CIOs
By Richard Koman
March 31, 2008 12:10PM

    Bookmark and Share
The Hannaford Brothers grocery chain may have been PCI compliant, but that doesn't protect against an inside job. The theft of card data in transmission came after malware was installed on all of Hannaford's servers. The Hannaford breach compromised 4.2 million cards and shows the need to enforce tighter internal IT controls.
 

Related Topics

Hannaford
PCI
Malware



In what was possibly an inside job, thieves worked a massive data Relevant Products/Services breach on the Hannaford Brothers grocery chain, installing malware on servers in each of the company's 300 grocery stores. The software captured credit- and debit-card data when consumers swiped cards -- and sent the data overseas, the company reported on March 17.

The attack represents a "new and sophisticated" attack on computer networks, the company told the Massachusetts attorney general and the state's consumer-affairs agency.

The Hannaford breach is notable because -- unlike the notorious breach of The TJX Companies in 2006 -- the company did not store the customer Relevant Products/Services data. Rather, the hackers captured the stream of data as card information was sent to banks for verification.

Inside Job?

The scheme may have compromised 4.2 million cards used at the stores between Dec. 7 and March 10, the company said. About 2,000 cases of fraud have been linked to the Hannaford breach.

The Hannaford breach appears to have been a professional, sophisticated attack, said Andrew Storms, director of security operations at nCircle Network Security, in an e-mail. "The means by which the malware was introduced and the data extracted only furthers the speculation that Hannaford was victim to a sophisticated attack," he said. "We have further information in the last few days that indicate this may have been an inside job, which seems to nicely explain some of the bigger questions."

The questions include how was the malware introduced and why was the attack so successful? "For example, it's unlikely that an outsider would have had such an incredibly high success rate at distributing the correct malware to all the correct systems," Storms said.

Furthermore, writing sophisticated software to intercept credit-card information at the time of a card swipe means "an attacker would have needed to have some prototype systems in-hand first to develop and test the system Relevant Products/Services prior to deployment Relevant Products/Services," Storms said.

Lessons for CIOs

What are the lessons of the Hannaford breach for CIOs?

The event signals that exploits don't always originate on the outside, said Storms. "So many companies spend too much time fighting the attacker by building a fortress around their network Relevant Products/Services with the idea that all risks are going to attack from a given direction. What you end up with is a network that's hard and crunchy on the outside, but gooey on the inside."

As for Hannaford, "a system which processes credit-card data unencrypted has no reason to have line of sight of the Internet," Storms said. "And if it must, then reduce the risk through mitigation strategies like content inspection, monitoring, log analysis and stricter controls on who can alter those systems."

Finally, Hannaford was compliant with the Payment Card Industry security standards, which specifies how companies are to build a secure network, protect cardholder data, manage vulnerability programs and other methodologies. How could a PCI-complaint enterprise Relevant Products/Services suffer such a breach?

For one thing, Hannaford might have fallen out of compliance, Storms said. But even if it was complaint at the time of the breach, "PCI compliance is not a panacea. It cannot cover every aspect of every distinct merchant network," Storms said.
 

Tell Us What You Think
Your Comment:



Advertisement


 Computing
1.   Intel Launches Itanium 9300 Series
2.   Nvidia Auto-Switches Notebook GPU
3.   MS: Windows 7 Doesn't Hurt Battery
4.   Tips for More Windows 7 Productivity
5.   The Pros and Cons of Apple's iPad


advertisement
EPIC Objects To Google-NSA TiesEPIC Objects To Google-NSA Ties
Cyberattack meant to rattle Google?
Average Rating:
Symbian 3 Is Now Fully Open SourceSymbian 3 Is Now Fully Open Source
But mobile OS remains linked to Nokia.
Average Rating:
Google Attack Highlights Black MarketGoogle Attack Highlights Black Market
Paying for bug info is hotly debated.
Average Rating:


advertisement
Product Information and Resources for Technology You Can Use To Boost Your Business

Enterprise Hardware Spotlight
Nvidia Auto-Switches Notebook GPU To Save Battery Life
Nvidia has taken the wraps off a notebook technology that chooses the best graphics processor for any given application and automatically routes the workload to Nvidia or Intel processors.
 
Microsoft Says Battery Woes Not Caused By Windows 7
Battery problems on Windows 7 machines are not caused by the operating system. That's the position of Stephen Sinofsky, head of the Windows division, in a long posting on the Windows engineering blog.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 

Enterprise Technology Spotlight
Intel Launches Quad-Core Itanium 9300 Series Processor
After two unexpected delays, Intel has launched the Itanium 9300 series, a 64-bit, quad-core processor code-named Tukwila that is expected to double the performance of its predecessor.
 
Google May Add Facebook, Twitter Links to Gmail
Google will reportedly roll more social-networking features into Gmail, the fastest-growing e-mail service. The new features could save users the trouble of switching to Facebook or Twitter.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Hardware | Software | Communications | Network Security | Wireless Tech | Linux/Open Source
Apple/Macintosh | Microsoft/Windows | World Wide Web | Data Storage | E-Commerce | Personal Tech | Tech Trends | Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo.