Cost Plus World Market is another retailer, where customers were unknowingly giving criminals access to their bank accounts when they made a purchase.
On July 22nd, the company announced that after a thorough investigation they learned the Electronic Funds Transfer devices (PIN pads) might have been been compromised at eight Southern California stores by unauthorized third parties.
Since then three additional stores have been identified as being compromised.
The first hint of trouble was in June when two employees reported unauthorized transactions on their debit cards. By early July, the banks were reporting a unusual amount of fraud accounts that had one thing in common, they had been used at Cost Plus.
I picked up this story in an article on SignonSanDiego.com published yesterday (08/22/08). The only other mention of it, I could find was in a report by FOX News on 7/22/08.
Both the SignonSanDiego.com article and the official press release state that only debit and not credit cards have been reported compromised. Given that the hardware compromised accepts both credit and debit cards for payment, my humble guess is that credit card information might have been compromised, also. The reality is that you need both a card number and a PIN to get cash. The other reality is that card numbers can often be used without a PIN. My guess is that (at least so far) the crooks behind this were after fast cash.
Cost Plus is working with their payment card processors and the banks to identify customers, who might have been compromised. They have also brought in a external data security vendor (Verizon Business/Cybertrust) to analyze their systems. PIN pads are being replaced in all their stores, nationwide.
Compromises involving PIN pads have become more frequent in recent years. Cases are now being seen despite the fact that the retailer was compliant with payment card industry security standards. Speculation is that this is done when the information is being transmitted internally before it is transmitted to a payment card processor. Once the internal system is compromised, the hackers use sniffer programs to gather all the information and a data compromise is born.
In the early reports of PIN pad compromises, the actual PIN pads were being replaced. The crooks would later come back and in and retrieve the PIN pad to gather the payment card information or pick up via a wireless connection.
Since then my speculation is that the hacking methods being used have become more sophisticated and PCI data protection standards -- designed to protect merchants from data compromises -- might no longer be 100 percent effective.
Data compromises cost the victim affected, the retailer and the financial institutions issuing the payment cards.
I tend to write on behalf of the victim and I wanted to point to an excellent article by Tom Fragala, where he analyzes the protections offered when using credit and debit cards. General consensus is that it is a lot safer to use a credit card from a consumer point-of-view. Note I'm saying this from a security point-of-view because too much credit card debt isn't always a good thing, but that's a whole other subject.
Tom is a fellow blogger, and the CEO of a privacy friendly identity theft protection service (Truston) that just won another in what is becoming a long string of awards. They also offer a 45 day (completely) free trial to use their services.
As long as there is a lot of money to be stolen from payment cards, criminals are going to be motivated to defeat security fixes.
The recent news that one of these retail hacking rings were caught and put behind bars probably will go a lot farther in preventing data compromises than security fixes, which seem to be counter-fixed, fairly frequently.
The eleven Cost Plus Stores known to have been compromised were San Diego (372 Fourth Avenue, San Diego, CA 92101); Oceanside (2140 Vista Way, Oceanside, CA 92054); La Jolla (8657 Villa La Jolla Drive Suite 117, La Jolla, CA 92037); Mission Viejo (28341 Marquerite Parkway, Mission Viejo, CA 92692); San Dimas (638 West Arrow Highway, San Dimas, CA 91773); Valencia (25676 North The Old Road, Valencia, CA 91381); Palm Desert (44-439 Town Center Way, Palm Desert, CA 92260); Oxnard (221 Esplanade Drive, Oxnard, CA 93030); Westlake Village (Thousand Oaks) (160 Promenade Way, Westlake Village, CA 91362); Tucson East (5975 E. Broadway, Tucson, AZ 85711); and Tucson (4821 North Stone Avenue Tucson, AZ 85704).
Cost Plus also has a FAQ page for people, who think they may have been compromised.
Showing posts with label data-breach. Show all posts
Showing posts with label data-breach. Show all posts
Saturday, August 23, 2008
Sunday, January 20, 2008
Do secure storage/destruction facilities really protect information from theft?
Information by it's very nature is hard to inventory. Let's face it, it isn't cash or precious gems and it can be copied in a LOT of different ways.
This fact also gives the entity losing it a lot of deniability. Most of the time, it's impossible to be 100 percent sure what happened to any information discovered missing.
Could a tape gone missing at a secure storage facility owned by Iron Mountain containing 650,000 customer files reveal that these facilities provide us with a false sense of security?
Robert McMillian at Computer World is reporting the latest information on this story:
Secure storage/information destruction businesses have seen explosive growth due to all the compliance regulations we've seen enacted in recent years.
Many of them, including Iron Mountain advertise state of the art physical security standards. I did take the time to watch the videos on this at the Iron Mountain site, and although they are impressive, the measures they take are pretty common at most secure buildings.
Secure buildings have been burglarized before.
I would also guess that even if external compromise was ruled out, it can be stolen by anyone who has been given access to it. Again, we are dealing with a commodity that is hard to inventory and can be reproduced (copied) in a lot of different ways.
Another point to reflect on is that a lot of this information is brought to these facilities to be destroyed. Since the information being destroyed isn't inventoried, it's probably impossible to go back and verify whether the information was actually destroyed.
My guess is that the biggest threat to information stored at these facilities are human beings, who make mistakes or can intentionally commit wrongdoing.
How valuable would a plant, or a recruit be to a identity theft gang in one of these facilities? My guess also is that as long as they were not very greedy, they could probably operate for a long time and never get caught.
Again, it is very hard to inventory information, which make theft detection difficult, also.
When watching Iron Mountain's security videos, they mention that they put their employees through extensive background tests. In today's world, with all the stolen identities and counterfeit documents available, the effectiveness of background checks is questionable, also.
To support this, I would point to the fact that millions of illegal immigrants seem to have no problem passing them.
Please note, I'm not worried about the illegal immigrants trying to make a better life for themselves. The problem is all the criminals, who hide in the camouflage the illegal immigration phenomenon provides.
So far as the people coming here to earn a decent living, they wouldn't be here if there weren't a lot of jobs available to them.
I don't want to pick on Iron Mountain too much. They aren't the only players in this growth industry. In fact, the security they provide is probably as good, or better than most of their competition.
The problem is that in actuality, they are just one more place information can be compromised. By their very nature these facilities are a point of consolidation for sensitive information. This makes them a lucrative target for those in the information theft business.
A wise man once said, the best way to protect information is to not store it in too many places in the first place. Unfortunately, as long as information is worth a lot of money, we will probably continue to ignore this sage advice.
The good news is that in this case, we know what information was stolen. This means that measures can be taken to prevent it from being used to commit crimes.
Computer World article by Robert McMillan, here.
This fact also gives the entity losing it a lot of deniability. Most of the time, it's impossible to be 100 percent sure what happened to any information discovered missing.
Could a tape gone missing at a secure storage facility owned by Iron Mountain containing 650,000 customer files reveal that these facilities provide us with a false sense of security?
Robert McMillian at Computer World is reporting the latest information on this story:
A backup tape containing credit-card information from hundreds of U.S. retailers is missing, forcing the company responsible for the data to warn customers that they may become the targets of data fraud.Please note, there are reports that 230 retailers lost information and JC Penny is just one of them.
GE Money, which manages in-store credit-card programs for the majority of U.S. retailers, first realized that the tape was missing from an Iron Mountain secure storage facility in October, said Richard Jones, a company spokesman. "We were informed that one of the tapes could not be located. But at the same time there was no record of it ever having been checked out," he said.
The tape contained in-store credit-card information on 650,000 retail customers, including those of J.C. Penney, he said. GE Money employees are also affected by the breach.
Secure storage/information destruction businesses have seen explosive growth due to all the compliance regulations we've seen enacted in recent years.
Many of them, including Iron Mountain advertise state of the art physical security standards. I did take the time to watch the videos on this at the Iron Mountain site, and although they are impressive, the measures they take are pretty common at most secure buildings.
Secure buildings have been burglarized before.
I would also guess that even if external compromise was ruled out, it can be stolen by anyone who has been given access to it. Again, we are dealing with a commodity that is hard to inventory and can be reproduced (copied) in a lot of different ways.
Another point to reflect on is that a lot of this information is brought to these facilities to be destroyed. Since the information being destroyed isn't inventoried, it's probably impossible to go back and verify whether the information was actually destroyed.
My guess is that the biggest threat to information stored at these facilities are human beings, who make mistakes or can intentionally commit wrongdoing.
How valuable would a plant, or a recruit be to a identity theft gang in one of these facilities? My guess also is that as long as they were not very greedy, they could probably operate for a long time and never get caught.
Again, it is very hard to inventory information, which make theft detection difficult, also.
When watching Iron Mountain's security videos, they mention that they put their employees through extensive background tests. In today's world, with all the stolen identities and counterfeit documents available, the effectiveness of background checks is questionable, also.
To support this, I would point to the fact that millions of illegal immigrants seem to have no problem passing them.
Please note, I'm not worried about the illegal immigrants trying to make a better life for themselves. The problem is all the criminals, who hide in the camouflage the illegal immigration phenomenon provides.
So far as the people coming here to earn a decent living, they wouldn't be here if there weren't a lot of jobs available to them.
I don't want to pick on Iron Mountain too much. They aren't the only players in this growth industry. In fact, the security they provide is probably as good, or better than most of their competition.
The problem is that in actuality, they are just one more place information can be compromised. By their very nature these facilities are a point of consolidation for sensitive information. This makes them a lucrative target for those in the information theft business.
A wise man once said, the best way to protect information is to not store it in too many places in the first place. Unfortunately, as long as information is worth a lot of money, we will probably continue to ignore this sage advice.
The good news is that in this case, we know what information was stolen. This means that measures can be taken to prevent it from being used to commit crimes.
Computer World article by Robert McMillan, here.
Wednesday, February 28, 2007
Could the arrests in the Stop and Shop data breach indicate a tie to Armenian Mobsters?
Stop & Shop has recently been in the news because of a data breach, involving compromised debit and credit card information. The data breach was traced to PIN pads that had been mysteriously replaced.
To read my original post on the Stop & Shop data-breach, link here.
Monday night, Stop & Shop employees spotted four individuals attempting to remove PIN pads at one of their stores. Police were notified, store video was shared with them, and four arrests were eventually made.
After the disclosure, Stop & Shop bolted down the PIN pads at all their stores. Some believe this helped slow the crooks down long enough to be noticed.
Despite this, some alert employees certainly deserve some recognition.
The Rhode Island police published some of the video stills of the suspects in action, here.
Ray Henry of the AP is reporting:
The men were arrested Monday night while attempting to switch keypads at a store in Coventry, police said. A store security officer called police after employees noticed one suspect trying to remove a keypad while two others were seeking to distract workers.Data breaches have become a huge issue, with new reports surfacing (it seems) every week. Over 100 million Americans have had their information compromised since 2005, according to the Privacy Rights Clearinghouse, which has maintained a chronology of these occurrences.
Arutyun Shatarevyan, 20, Mikael Stepanian, 28, Gevork Baltadjian, 20, and Arman Ter-Esayan, 22, were arrested and charged with conspiracy, computer theft and fraud. They were scheduled to be arraigned Tuesday afternoon in Kent County District Court.
AP story, here.
Interestingly enough, the arrested individuals are from California. Judging by their surnames, they are of Armenian descent. This brings to mind a previous breach, where two fraudsters were charged after a data breach at Dollar Tree - they were also from California and have Armenian surnames.
Parkev Krmoian was arrested in the Dollar Tree episode and (at the time), a picture of his friend was being circulated (who was still at large), here.
Armenian organized crime is a big problem in Glendale (where Krimoian was from), and they are known to be involved in "lucrative white collar crimes," such as credit-card fraud. Glendale and Hollywood in Southern California has the largest Armenian population outside of Armenia.
If you are interested in learning more about Armenian organized crime, ARMENIANDIASPORA.com has a nice little write-up, here.
Placing skimming devices in public places is a growing phenomenon, Tom Fragala (MyTruston) did a great post on this (with video), here.
The video is pretty amazing!
Subscribe to:
Posts (Atom)

