Showing posts with label target. Show all posts
Showing posts with label target. Show all posts

Wednesday, May 7, 2014

The Reach of a Breach

It comes as no surprise that the CEO of Target has resigned in the wake of their massive data breach. The 2nd executive, if I remember correctly, to resign due to the mishap. Data breaches are costly according to the most recent Ponemon 2014 Cost of Data Breach Study: United States and the main reason for the steep increase in costs is 'the loss of customers following the data breach due to additional expenses required to preserve the organization's brand and reputation.' The cost of each lost or stolen record, on average, increased from $188 to $201 per record from 2012 to 2013 - a 9% increase.

But that's not all, In 2013, there appeared to be 'an abnormal churn rate' of 15% of customers abandoning companies, especially those in financial services, hit by a breach says Ponemon. I'm always curious about that. I usually avoid stores that have been recently compromised wondering if something is lingering yet think, they gotta be on high alert, especially with law enforcement involved. Maybe it's as safe as it ever will be.

A recent Courion survey of IT security executives showed that 78% of respondents say they're anxious about the possibility of a data breach at their organization. If there were a massive security breach at these companies, 58.8% said 'protecting the privacy of our customers' would be top priority and 62.7% would lament about 'negative publicity affecting the company brand' due to the breach. Maybe that's the problem. They're more worried about their image than they are of protecting our info. It's the 58.8% you want to shop at.

Reaching for more, Symantec’s Internet Security Threat Report (ISTR), Volume 19, shows a big change in cybercriminal habits, revealing the bad guys are plotting for months before pulling off the huge heists – instead of popping quick hits with smaller bounty. One big is worth fifty small. In 2013, there was a 62% uptick in the number of data breaches exposing more than 552 million identities. That's about 10% of the planet's population, give-or-take.

And finally, there have been a few companies that have gone out of business due to a leakage but a few months ago a data breach also closed some Seattle area Catholic schools. According to the Seattle Archdiocese, at least three Roman Catholic parishes and the Archdiocese’s chancery offices had been targeted by a tax-fraud scheme. In order to allow those who were victims time to contact the appropriate institutions during school hours, they cancelled classes. How's that for reach.

ps

Related:

 

 

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Wednesday, January 15, 2014

Bricks (Thru the Window) and Mortar (Rounds)

...or I've been Breached.

There was a time when people differentiated between stealing from a physical store and pilfering data from a network.  Throughout the years there have been articles talking about the safety/risks of shopping online vs. shopping at a retail outlet.  You could either get carjacked in the parking lot and have your wallet stolen on Black Friday or your browser hijacked and your digital identity stolen on Cyber Monday.  There are probably many people who exclusively shop one way or another due to their own risk assessment of each...ignoring whatever convenience, interaction, price, constraints, gratification, availability or any other perceived beneficial metric on the Franklin T-scale tied to the specific activity.

Now we've learned that the recent Target breach was due to malware being installed on the point of sale devices.  Wait, what?  A 'cyber' crime within a retail bricks environment?  Isn't anything sacred?  Well no, and this is really not anything new.  ATMs and point of sale devices have been targets for a while due to the simple fact that they run on an operating system.  A potentially vulnerable operating system.  In 2012, thieves broke into Barnes and Noble's keypads and grabbed a bunch of credit cards.  Subway also had it's PoS devices infiltrated.  There will be more.

Online shopping has risen 300% since 2004 and continues to grow.  comScore reports that desktop sales on Black Friday grew 21% ($1.1 Billion) and Cyber Monday grew 18% ($1.7 billion).  Yet, with all the mouse orders we accomplish on any given day, according to the Dept. of Commerce, it still only amounts to 6% of all U.S. retail sales.  You'd think that it would be much higher but major purchases, like automobiles for instance, are still (mostly) purchased in person.  The shift, however, will certainly grow as more people rely on mobile as a primary purchase sidekick and... as always, the bad guys are going to focus on where they can get their take.  In this interesting TED talk, security expert Mikko Hypponen says that we are more likely to be a victim of an online crime than a real world stick up.

That includes an increase of blended attacks.

We've seen it a thousand times - plant something on the inside and siphon from the outside; launch a network based attack as a diversion to go after the app data; do a little social engineering surveillance to become one of them; and of course the classic, knock out the guards, put on their outfits and walk in while nobody notices.

There is still much to uncover about this latest breach but I can't help feeling that more retailers, as has been reported, will be screaming, 'This PoS device is a PoS

Nice how I worked that in huh?

ps

Related:

 

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, January 7, 2014

OK 2014, Now What

So I've been staring at this blinking cursor for the last 5 minutes wondering what story to tell.  'Once upon a time, there was a....'  No that won't work.  'It was a dark and dreary night as our protagonist grudgingly dragged his feet toward the impending...'  No, not that either.  How about, 'The waves were big, mean and fast that day...the kind of day where Eddie would go.'   Nah, too local boy.
After a few weeks break and with so much going on within information technology, I sometimes find it difficult to zero in on something interesting with so many choices.  So I decided to do a mini blog buffet....the best in town, I say!
The big news this week seems to be the Consumer Electronics Show (CES).  From connected and driverless cars to interactive kitchens to wearable technology to the massive ultra HD televisions to even toothbrushes, the internet of things is certainly posed to take over the world in 2014.  There are, of course, risks with all these embedded systems.
There was the Target breach right at the height of the holiday shopping season nailing 40 some million (now 70 million) credit and debit cards in the process.  I had a browser tab The 10 Worst Data Breaches of 2013 saved since before the new year for an article but this most recent debacle will certainly make all of 2014's lists.  I was in Target a couple days ago retuning something and the person in front of me was asked, 'Do you want cash or credited back on the card?'  He dryly answered, 'Well, I got a letter from my bank this week saying they are replacing my card due to your breach, so I'll just take the cash.'  Mine was an even exchange.
There was the FireEye - Mandiant deal struck slightly before the ball dropped and announced after the 12th ding.  Interesting blend of attack detection along with attack response.  The timing seemed perfect in the wake of the Target news.
There was the Snapchat breach, the Yahoo malware, the WoW attack and certainly all the 'national security' news.
And finally, our very own John McAdam earned Puget Sound Business Journal Executive of the Year for 2013.  I first met John when I joined F5 in 2004.  We had less than 1000 employees at the time and our sales conference that year was at a local Seattle hotel.  During one of the breaks, Ken Salchow took me over to introduce me to McAdam, who was sitting in a chair fiddling with his blackberry.  Now you'd think that the first time meeting your CEO you'd be all proper, business-like...Sir.  Not me.  As Ken did the formalities, the first words out of my mouth were, 'What's your high score on brick breaker?'  John's face lit up with a smile, a determination in his eye and without missing a beat, shoved his phone in my face and taunted, 'Can you beat that?'  It was wonderful and crushing at the same time since his score trounced mine.  This was well before internet on planes and playing brick breaker was a way to pass time in the air.  For the next several months as we did our individual business travel, we would send each other our high score(s) wrapped in a bit of bragging.  There was actually a few of us on the thread, all hoping to blast the others.  Then one day, one of the competitors (who had been on an overseas flight if I remember correctly) sent a score that blew everyone away.  That was it, game over.  But I'll never forget how the CEO included a relatively new guy into a fun little group of folks trying to one up each other.  I've been here ever since. 
Welcome to the Year of the Horse!
ps
Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]