TulipTools Internet Business Owners and Online Sellers Community

Full Version: 4.2 Million Credit Cards Compromised in Supermarket Point of Sale Data Breach
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Quote:It turns out malware had somehow found its way onto a Maine-based supermarket chain's servers, which led to the security breach announced earlier this month compromising up to 4.2 million credit cards.

Citing a letter the Hannaford grocer sent to Massachusetts regulators, The Boston Globe on Friday reported the malicious software intercepted data from customers as they paid with plastic at checkout counters and sent data overseas...

full article: http://www.news.com/8301-10784_3-9905991...g=nefd.top

Quote:... malware was installed on servers at every store in the Hannaford chain -- approximately 300 locations.

According to the letter, the malware intercepted the credit card number and expiration date at the point of sale as it was being sent for authorization. The malware then sent batches of card numbers over the Internet to a foreign ISP.

The article calls the attack "new and sophisticated," but was it really? I'll grant that compromising hundreds of servers and then sniffing the point-of-sale traffic to gather the account data is pretty slick.

But it also seems to me that Hannaford's security processes failed in several areas where security processes just shouldn't these days...

full article: http://www.informationweek.com/blog/main...f_ser.html
US restaurant chain Dave & Busters hit by a similar point of sale breach:

Quote:The restaurant-slash-arcade-slash-bar Dave & Buster's is the latest U.S. outlet to suffer a breach of its credit card processing system. Hackers based in Ukraine and Estonia -- assisted by a guy in Miami -- installed packet sniffer malware at the point of sale systems in several D&B outlets...

This breach, much like one a few months ago at the East Coast grocery chain Hannaford, was the result of strategically placed malware that recorded credit card data in transit. These breaches illustrate the need for more stringent payment card security standards...

full article: http://ecommercetimes.com/story/Breaches...62982.html