Monday, September 15, 2008

Forever 21 Clarifies Data Breach Details


Evan Schuman writes on StorefrontBacktalk:

On Sept. 12, Forever 21 issued a statement that the chain had been wirelessly breached repeatedly between March 25, 2004, and Aug. 14, 2007, and that thieves "accessed older credit and debit card transaction data for approximately 98,930 credit and debit card numbers," including about 20,500 card numbers taken from one particular store in Fresno, Ca.. "The data included credit and debit card numbers and, in some instances, expiration dates and other card data, but did not include customer name and address. More than half of the affected payment card numbers are no longer active or have expired expiration dates."

It's not clear what the "other card data" was but expiration date retention was likely not in compliance with PCI rules, but it's possible that data could have been grabbed during authorization verification. Forever 21's statement said that "our systems have been certified to be in compliance with the PCI standards, including the data encryption standards," but it didn't say specifically when they were certified, other than "since 2007."

The Forever 21 statement was also vague on information about how and when it learned of the breach. Similar to a statement issued by fellow TJX Breach victim Barnes & Noble, Forever 21 now says that it was contacted by the U.S. Secret Service on the morning of Aug. 5, 2008, "and was advised that our company was identified in the indictment as one of the retail victims."

More here.

Thursday, October 02, 2008

Forever 21: PCI Auditor Missed 5-Year-Old Transaction Data

Evan Schuman writes on StorefrontBacktalk:

As more details drip out from Forever 21's data breach of almost 100,000 payment cards, the chain now says it had been certified PCI compliant, despite having stored complete card information from as far back as 2003.

"The files were inadvertently retained within other data files and this was not uncovered by the assessor," a statement from the chain said. (Our story from last week has been updated with the new information, along with a link to the earlier report of the breach.)

This is proving to be a frightening trend, with retailers believing they are compliant and much later on discovering various pockets of forbidden data scattered through their network.

More here.

Thursday, August 07, 2008

The Mysterious Unidentified Retailer In The TJX Indictments

Evan Schuman writes on StorefrontBacktalk:

The feds were certainly not shy about naming retail victims in the 41 million payment card heist, listing in one of the indictments TJX, BJ's Wholesale Club, OfficeMax, Boston Market, Barnes & Noble, Sports Authority, DSW and Forever 21.

But the mystery retailer had several differences from the other retailers. First, this retailer was the only one whose perimeter security systems detected the mouse-toting bandits, although it did so only after the binary bullies had grabbed some card numbers, including some ATM PINs.

Therein may lie the reason for this retailer's mask. On the one hand, this Fortune 500 merchant is an unsung hero in breaking this case. Not coincidentally, that chain was the final one the defendants wirelessly hacked into through a Florida wireless access point. Blocked of their last system in mid-October 2007, one of the two men charged with attempting that final cyber thievery today faces life in prison, if convicted of all charges.

More here.

Thursday, January 08, 2009

Carder Linked to TJX Hack Jailed for 30 Years by Turkish Court

John Leyden writes on The Register:

A Ukrainian fraudster linked to the infamous TJX hack was sentenced to a 30 year prison sentence in Turkey on unrelated charges this week.

Maksym Yastremskiy (AKA Maksik) was found guilty of hacking into the computer systems of 12 Turkish banks, as well as committing computer fraud against them, according to local reports. The court also reportedly fined Yastremskiy $23,200.

Yastremskiy was arrested by police in Turkey in July 2007, after visiting a nightclub in the beach resort of Kemer, in an operation US law enforcement agencies soon realised was key to unraveling the TJX hacking case.

It emerged within weeks that Yastremskiy was fencing hundreds of hundreds of thousands of credit card numbers linked to hacking attacks at US retail outlets, including TJX, through various underground carders forums. Yastremskiy was charged last August with trafficking in stolen credit card information harvested from a string of retail firms including TJX, OfficeMax, Barnes & Noble, Forever 21, DSW, and Marshall's, among others.

Alleged ringleader Albert "Segvec" Gonzalez of Miami allegedly conspired with ten other suspects (including Yastremskiy) to hack into the insecure networks maintained by the US retailers and lift 40 million credit and debit card numbers. Since the heist against TJX alone affected 45.6 million customers alone these colossal figures are, if anything, a possible underestimate of the possible extent of the crime.

More here.

Tuesday, August 05, 2008

U.S. Dept. of Justice Charges 11 in Theft of 40 Million Card Numbers

A Reuters newswire article, via The New York Times, reports that:

The Justice Department said on Tuesday that it had charged 11 people in the theft of tens of millions of credit and debit card numbers of customers shopping at major retailers, including TJX Companies, in one of the largest reported identity-theft incidents on record.

The United States Attorney in Boston said those charged were involved in the theft of more than 40 million credit and debit card numbers.

TJX, of Framingham, Mass., which owns the Marshall’s and TJ Maxx chains, was the hardest hit by the ring, acknowledging in March 2007 that information from 45.7 million credit cards was stolen from its computers.

The charges focus on three people from the United States, three from the Ukraine, two from China, one from Estonia and one from Belarus.

The authorities said that the scheme was spearheaded by a Miami man named Albert Gonzalez, who hacked into the computer systems of retailers including TJX, BJ’s Wholesale Club, OfficeMax, Boston Market, Barnes & Noble, Sports Authority, Forever 21 and DSW Inc. The numbers were then stored on computer servers in the United States and Eastern Europe.

They then sold the information to people in the United States and Europe, who used it to withdraw tens of thousands of dollars at a time from automated teller machines, the authorities said.

More here.

Thursday, August 20, 2009

Gonzalez's Lawyer to Contend He Was Not The Kingpin of Heartland, Hannaford Breaches

Jaikumar Vijayan writes in ComputerWorld:

The attorney for Albert Gonzalez, the man indicted Monday on charges related to the massive data thefts at Heartland Payment Systems and four other retailers, claims it was another member of Gonzalez's gang who was the real leader of the heists.

In an interview with the New York Times, Gonzalez's lawyer, Rene Palomino, said he was prepared to argue that the person who organized the break-ins at Heartland and elsewhere was really Damon Patrick Toey of Miami.

Palomino said Toey is the individual who was identified only as "P.T," an unindicted co-conspirator in Monday's indictment papers. Palomino also told the Times that one of the unnamed Russian conspirators mentioned in the indictment is an individual named Maksym Yastremskiy, who is currently serving a 30-year sentence in a Turkish prison.

Toey was one of 11 individuals, including Gonzalez, who were indicted last year on charges related to the data thefts at TJX Companies Inc., Dave & Busters, BJ's Wholesale Club, OfficeMax, Boston Market, Barnes & Noble, Sports Authority, Forever 21 and DSW.

More here.

Friday, October 31, 2008

New York Coder Charged With Helping TJ Maxx Hacker

Kevin Poulsen writes on Threat Level:

A New York man was hit with a federal conspiracy charge this week for allegedly lending his programming expertise to the head of a hacking gang accused of stealing and selling over 40 million credit and debit card numbers.

Stephen Watt, 25, allegedly customized a packet-sniffing program called "blabla" for use by Albert Gonzalez, a former Secret Service informant who was indicted earlier this year as the mastermind of a 2005-2007 intrusion into clothier T.J. Maxx, as well as breaches at BJ’s Wholesale Club, Boston Market, Barnes & Noble, Sports Authority, Forever 21, DSW and OfficeMax.

Gonzalez allegedly used sniffers to scoop up credit and debit card numbers from hacked networks as they sped from cash registers to processing servers. Watt modified blabla "on diverse dates" to meet Gonzalez's evolving needs, according to the one-count federal information [.pdf] filed in federal court in Boston on Wednesday.

More here.

Thursday, September 18, 2008

Retail Security: 'Knee-jerk' Standards Compliance Isn't Enough

Tim Greene writes on NetworkWorld:

Businesses certified to be compliant with the Payment Card Industry Data Security Standards (PCI DSS) keep suffering data breaches, but the problem may be more with the way businesses address the requirements than with the PCI standard, experts told an Interop gathering.

Retail chain Forever 21, which last week revealed that nearly 99,000 customer payment cards may have been compromised, claimed it was PCI compliant, said John Pironti, the chief information risk strategist for Getronics.

“They claim to be PCI compliant, Hannaford’s [the supermarket chain that suffered a data breach] claimed to be PCI compliant,” said Pironti, who moderated an Interop panel on the subject of compliance.

But those firms may have restricted compliance auditors’ access to areas where they thought they would meet standards, said Jennifer Mack, vice president of Master Card Worldwide and a member of the PCI Security Council.

More here.

Saturday, August 11, 2007

UK: Database of Top-Secret Police Phone Taps Stolen - UPDATE

Ruth Elkins writes in The Independent:

Police chiefs have launched a major investigation after the theft of a computer database containing thousands of top-secret mobile phone records from terrorism and organised crime investigations.

Scotland Yard is concerned that crucial evidence from undercover investigations could be lost forever or has found its way into "the wrong hands" after the computer and other IT equipment disappeared from a private firm in Sevenoaks, Kent, last Monday night after a break-in.

Forensic Telecommunications Services, whose clients include Scotland Yard, The Police Service of Northern Ireland, HM Revenue and Customs and the Crown Prosecution Service, specialises in tapping mobile phone calls made by criminal suspects. The stolen security-protected server contained the minutiae of phone calls it had screened, including the identity of the person who had made the call, as well as the exact time and location of the suspect when the call was made.

In a statement released to The Mail on Sunday, Forensic Telecommunications Services confirmed that the equipment had been stolen from its offices but denied that its disappearance would impact negatively on current police cases.

Yeah. Right. - ferg

More here.

UPDATE: 10:35 PDT, 21 August 2007: Apparently UK police has recovered the database. Details here.