Thursday, October 16, 2014

Kmart and Dairy Queen Report Data Breach

Target found the problem and let people know about it earlier, and what was their reward? Lost sales and closed stores.

http://bits.blogs.nytimes.com/2014/10/10/kmart-and-dairy-queen-report-data-breach/

By Nicole Perlroth
October 10, 2014

In the latest cyberattack on American retailers and restaurants, both Kmart and Dairy Queen said their computer systems were compromised in security intrusions involving customers’ credit and debit card information.

Kmart, a subsidiary of Sears Holdings, said on Friday that it had been breached and that it was working with law enforcement as well as a forensics team. The company said that it appeared to have been attacked in early September and that malware was present on some of its in-store payment systems. The malware, like the type found at Home Depot recently, was meant to evade antivirus systems.

Dairy Queen also said on Thursday that its in-store payment systems contained malware. The company said it was working with its franchisees to determine if and when each location was breached and posted a full list, with time frames, on its website. That information suggests hackers made their way into Dairy Queen payment systems in August.

Based on early forensics reports, Sears and Dairy Queen said there was no no evidence that personal information, debit card PINs, email addresses or Social Security numbers were obtained in the attack. Only account numbers and expiration dates were taken.

Sears and Dairy Queen join nearly a dozen retailers — including Target, Sally Beauty, Neiman Marcus, the United Parcel Service, Michaels, Albertsons, SuperValu, P.F. Chang’s and Home Depot — that have had their in-store payment systems compromised with malware over the last year.

The Secret Service estimated this summer that 1,000 American merchants were affected by this kind of attack, and that many of them may not even know that they were breached. There have been no arrests to date.

•••••

No comments:

Post a Comment